arXiv

GREAT: Generalizable Backdoor Attacks in RLHF via Emotion-Aware Trigger Synthesis

Title: GREAT: Generalizable Backdoor Attacks in RLHF via Emotion-Aware Trigger Synthesis

Abstract:

While recent studies have highlighted the vulnerability of Reinforcement Learning from Human Feedback (RLHF) to backdoor attacks, current methodologies are often constrained by their dependence on uncommon tokens or static triggers, which reduces their effectiveness in real-world applications. To address this limitation, we introduce GREAT, a new framework designed to implant natural distributional backdoors within RLHF systems. This approach specifically aims to induce harmful response generation among a specific vulnerable user demographic, characterized by semantically violent queries coupled with emotionally charged, angry triggers.

Central to GREAT is a trigger identification pipeline that functions within the model’s latent embedding space. By utilizing clustering algorithms and dimensionality reduction, the system pinpoints representative triggers. To facilitate this process, we developed a hierarchical prompting strategy focused on diversity to create "Erinyes," a curated dataset containing over 5,000 high-quality angry triggers generated using GPT-4.1. Experimental results demonstrate that GREAT surpasses baseline methods in generalizing attacks to previously unseen triggers, all while maintaining standard model utility and remaining undetected by existing defense mechanisms.


Source: arXiv Generated at: 2026-06-02 00:00:00 UTC

Related Articles

Law’s Billable Hour Is Being Shredded by AI
Bloomberg

Law’s Billable Hour Is Being Shredded by AI

AI is dismantling the billable hour by automating routine legal tasks. This technological shift threatens the traditiona...

Iran War: Trump Tries to Stop Israel’s Lebanon Push | The Opening Trade 6/2/2026
Bloomberg

Iran War: Trump Tries to Stop Israel’s Lebanon Push | The Opening Trade 6/2/2026

SoftBank in Early Talks to Back $800 Million Agile Robots Round
Bloomberg

SoftBank in Early Talks to Back $800 Million Agile Robots Round

SoftBank is in early talks to back Agile Robots’ $800 million funding round. The Japanese tech giant is currently in pre...

Amundi Is Diversifying Risk Via Commodity Currencies, Gold
Bloomberg

Amundi Is Diversifying Risk Via Commodity Currencies, Gold

Amundi diversifies risk by investing in commodity-linked currencies and gold. This strategy hedges against market volati...

Reuters

Marvell Technology surges after Nvidia's Huang calls it 'next trillion-dollar company'

Marvell Technology shares surged after Nvidia CEO Jensen Huang labeled the firm the “next trillion-dollar company.”

Russia Says It Found Foreign Spyware on Top Officials’ Phones
Bloomberg

Russia Says It Found Foreign Spyware on Top Officials’ Phones

Russia’s FSB claims to have discovered foreign spyware on senior officials’ phones. Moscow attributes the intrusion to h...