LLM-Assisted Red Teaming of Diffusion Models through “Failures Are Fated, But Can Be Faded”
In one sentence. An extension of the Failures Are Fated framework to text-to-image diffusion models with LLM-generated rewards and states, action screening inspired by design of experiments, and a comparison of DQN, PPO, and A2C for red teaming. AbstractIn large deep neural networks that seem to perform surprisingly well on many tasks, we also observe a few failures related to accuracy, social biases, and alignment with human values, among others. Therefore, before deploying these models, it is crucial to characterize this failure landscape for engineers to debug or audit models. Nevertheless, it is infeasible to exhaustively test for all possible combinations of factors that could lead to a model's failure. In this workshop paper, we improve the “Failures are fated, but can be faded” framework—a post-hoc method to explore and construct the failure landscape in pre-trained generative models—with a variety of deep reinforcement learning algorithms, screening tests, and LLM-based rewards and state generation. With the aid of limited human feedback, we then demonstrate how to restructure the failure landscape to be more desirable by moving away from the discovered failure modes. We empirically demonstrate the effectiveness of the proposed method on diffusion models. We also highlight the strengths and weaknesses of each algorithm in identifying failure modes. Note. Builds on Failures Are Fated, But Can Be Faded (ICML 2024 spotlight). BibTeX@inproceedings{sagar2024llmredteaming,
title = {LLM-Assisted Red Teaming of Diffusion Models through ``Failures Are Fated, But Can Be Faded''},
author = {Sagar, Som and Taparia, Aditya and Senanayake, Ransalu},
booktitle = {NeurIPS Workshop on Red Teaming GenAI: What Can We Learn from Adversaries?},
year = {2024}
}
Topicsred teaming, diffusion models, text-to-image, generative model safety, reinforcement learning, LLM-assisted evaluation |