Skip to content
Sprint projectNov 25, 2024

Classification on Latent Feature Activation for Detecting Adversarial Prompt Vulnerabilities

Hoang-Long Tran, Jack Kaunismaa, Edward Stevinson, Parv Mahajan, Oliver Clive-Griffin · Team Feature Disruption Lab

Submitted to Reprogramming AI Models Hackathon. Sprint projects are early-stage work by participants, not Apart Research publications.

Read the report

Report: Classification on Latent Feature Activation for Detecting Adversarial Prompt Vulnerabilities

Code (opens in new tab)
Share

We present a method leveraging Sparse Autoencoder (SAE)-derived feature activations to identify and mitigate adversarial prompt hijacking in large language models (LLMs). By training a logistic regression classifier on SAE-derived features, we accurately classify diverse adversarial prompts and distinguish between successful and unsuccessful attacks. Utilizing the Goodfire SDK with the LLaMA-8B model, we explored latent feature activations to gain insights into adversarial interactions. This approach highlights the potential of SAE activations for improving LLM safety by enabling automated auditing based on model internals. Future work will focus on scaling this method and exploring its integration as a control mechanism for mitigating attacks.

Reviews

Judging this Sprint?

Review this project

Your public critique appears on this page without your name. Your private critique is not published; only the Apart team reads it. If you agree below, we share your review with grantmaking.ai (opens in new tab) and the Transformative AI Fund so strong projects can be funded.

Not shown on this page.

Shown on this page, without your name.

Only the Apart team reads this, and funders if you agree below.

Share my name publicly on grantmaking.ai *
Share my private critique with funders *

Does the project contribute to the field of mechanistic interpretability? Does it provide new insights into understanding or steering AI model behavior? How well does it move us towards reprogramming AI models? How original and innovative is the approach?

How important is the contribution to advancing the field of AI safety? Do we expect the results to generalize beyond the specific case(s) presented in the submission? Does the approach introduce new safety mechanisms or enhance existing ones in innovative ways?

How well is the project executed from a technical standpoint?, Is the code well-structured, documented, and reproducible?, How effectively does it utilize Goodfire's SDK/API and other provided resources?, How clearly and effectively is the research presented in the paper?, Quality of visualizations and demos (if applicable), Clarity of methodology explanation and results interpretation

  1. This work covers an important problem and applies a sensible methodology. The performance of the results is impressive - I had to check in the code that the results were in fact on a test set. I'd be interested in seeing how often harmless prompts are misclassified though. Definitely worth extending further - these results are quite promising.

  2. This is addressing a really important practical problem. I liked their approach, am impressed with the results, and would be keen to see them build on this work!

Cite this project

@misc{tran2024classification,
  title = {{Classification on Latent Feature Activation for Detecting Adversarial Prompt Vulnerabilities}},
  author = {Hoang-Long Tran and Jack Kaunismaa and Edward Stevinson and Parv Mahajan and Oliver Clive-Griffin},
  year = {2024},
  month = nov,
  note = {Submitted to Reprogramming AI Models Hackathon, an Apart Research Sprint},
  howpublished = {\url{https://apartresearch.com/sprints/projects/classification-on-latent-feature-activation-for-detecting-adversarial-prompt-vulnerabilities}},
  url = {https://apartresearch.com/sprints/projects/classification-on-latent-feature-activation-for-detecting-adversarial-prompt-vulnerabilities}
}

Build something like this at the next Sprint

AI Collusion Research Sprint · Oct 23 - 25, 2026