Simple Assistive Task Linkage Probe#1319
Merged
jmartin-tech merged 8 commits intoNVIDIA:mainfrom Aug 6, 2025
Merged
Conversation
… Model simple assistive task. Update template.
jmartin-tech
reviewed
Aug 4, 2025
jmartin-tech
requested changes
Aug 4, 2025
Collaborator
jmartin-tech
left a comment
There was a problem hiding this comment.
Minor asks and enhancement ideas.
…d to using `garak.resources.api.nltk` in lieu of direct `nltk`.
jmartin-tech
approved these changes
Aug 6, 2025
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to subscribe to this conversation on GitHub.
Already have an account?
Sign in.
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Simple Assistive Task Linkage jailbreak technique from https://aclanthology.org/2025.findings-acl.100.pdf
Made some minor changes compared to their method. Specifically, using NLTK in lieu of GPT-4o. We also omit the
wiki_datathat they generate, opting for a marginally simpler task.May see some value by directly implementing more of their methodology. Specifically, we could directly use their pre-computed wiki data and the corresponding keys/prompts to replay what they've developed exactly. Code is available at: https://github.com/xndong/SATA
Verification
A pretty strong caveat here is that the mitigation detector is wildly insufficient -- lots of responses that almost satisfy the request but ultimately fail to.