From ASR to ASP: Evaluating Prompt Attack Vulnerabilities Against Open-Source LLMs
This paper comprehensively studies effective prompt injection attacks against 14 widely used open-source and three closed-source LLMs on five attack benchmarks and proposes a straightforward and effective hypnotism attack, showing that this attack causes aligned language models to generate objectionable behaviors.