Can Editing LLMs Inject Harm?

1Citations
Citations of this article
9Readers
Mendeley users who have this article in their library.
Get full text

Abstract

Large Language Models (LLMs) have emerged as a new information channel. Meanwhile, one critical but underexplored question is: Is it possible to bypass the safety alignment and inject harmful information into LLMs stealthily? In this paper, we propose to reformulate knowledge editing as a new type of safety threat for LLMs, namely Editing Attack, and conduct a systematic investigation with a newly constructed dataset EditAttack. Specifically, we focus on two typical safety risks of Editing Attack including Misinformation Injection and Bias Injection. For the first risk, we find that editing attacks can inject both commonsense and long-tail misinformation into LLMs, and the effectiveness for the former one is particularly high. For the second risk, we discover that not only can biased sentences be injected into LLMs with high effectiveness, but also one single biased sentence injection can degrade the overall fairness. Then, we further illustrate the high stealthiness of editing attacks. Our discoveries demonstrate the emerging misuse risks of knowledge editing techniques on compromising the safety alignment of LLMs and the feasibility of disseminating misinformation or bias with LLMs as new channels.

Cite

CITATION STYLE

APA

Chen, C., Huang, B., Li, Z., Chen, Z., Lai, S., Xu, X., … Shu, K. (2026). Can Editing LLMs Inject Harm? In Proceedings of the AAAI Conference on Artificial Intelligence (Vol. 40, pp. 30192–30200). Association for the Advancement of Artificial Intelligence. https://doi.org/10.1609/aaai.v40i36.40269

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free