@misc{spin:arxiv, author = "Zhou, Leon and Yang, Junfeng and Mao, Chengzhi", abstract = "Large Language Models (LLMs) are increasingly used in a variety of important applications, yet their safety and reliability remain as major concerns. Various adversarial and jailbreak attacks have been proposed to bypass the safety alignment and cause the model to produce harmful responses. We introduce Self-supervised Prompt INjection (SPIN) which can detect and reverse these various attacks on LLMs. Just by injecting an adaptive defense prompt at inference-time, our method is simple, effective, and compatible with existing safety-aligned models. Our benchmarks demonstrate that our system can reduce the attack success rate by up to 87.9\%, while maintaining the performance on benign user requests. In addition, we discuss the situation of an adaptive attacker and show that our method is still resilient against attackers who are aware of our defense.", title = "{SPIN}: Self-Supervised Prompt {IN}jection", month = "October", year = "2024", eprint = "2410.13236", archivePrefix = "arXiv", primaryClass = "cs.CL", url = "https://arxiv.org/abs/2410.13236", pdfurl = "https://arxiv.org/pdf/2410.13236" }