The WMDP Benchmark: Measuring and Reducing Malicious Use With Unlearning

  • 2024-03-06 21:27:11
  • Nathaniel Li, Alexander Pan, Anjali Gopal, Summer Yue, Daniel Berrios, Alice Gatti, Justin D. Li, Ann-Kathrin Dombrowski, Shashwat Goel, Long Phan, Gabriel Mukobi, Nathan Helm-Burger, Rassin Lababidi, Lennart Justen, Andrew B. Liu, Michael Chen, Isabelle Barrass, Oliver Zhang, Xiaoyuan Zhu, Rishub Tamirisa, Bhrugu Bharathi, Adam Khoja, Zhenqi Zhao, Ariel Herbert-Voss, Cort B. Breuer, Andy Zou, Mantas Mazeika, Zifan Wang, Palash Oswal, Weiran Liu, Adam A. Hunt, Justin Tienken-Harder, Kevin Y. Shih, Kemper Talley, John Guan, Russell Kaplan, Ian Steneker, David Campbell, Brad Jokubaitis, Alex Levinson, Jean Wang, William Qian, Kallol Krishna Karmakar, Steven Basart, Stephen Fitz, Mindy Levine, Ponnurangam Kumaraguru, Uday Tupakula, Vijay Varadharajan, Yan Shoshitaishvili, Jimmy Ba, Kevin M. E
  • 0

Abstract

The White House Executive Order on Artificial Intelligence highlights therisks of large language models (LLMs) empowering malicious actors in developingbiological, cyber, and chemical weapons. To measure these risks of malicioususe, government institutions and major AI labs are developing evaluations forhazardous capabilities in LLMs. However, current evaluations are private,preventing further research into mitigating risk. Furthermore, they focus ononly a few, highly specific pathways for malicious use. To fill these gaps, wepublicly release the Weapons of Mass Destruction Proxy (WMDP) benchmark, adataset of 4,157 multiple-choice questions that serve as a proxy measurement ofhazardous knowledge in biosecurity, cybersecurity, and chemical security. WMDPwas developed by a consortium of academics and technical consultants, and wasstringently filtered to eliminate sensitive information prior to publicrelease. WMDP serves two roles: first, as an evaluation for hazardous knowledgein LLMs, and second, as a benchmark for unlearning methods to remove suchhazardous knowledge. To guide progress on unlearning, we develop CUT, astate-of-the-art unlearning method based on controlling model representations.CUT reduces model performance on WMDP while maintaining general capabilities inareas such as biology and computer science, suggesting that unlearning may be aconcrete path towards reducing malicious use from LLMs. We release ourbenchmark and code publicly at https://wmdp.ai

 

Quick Read (beta)

loading the full paper ...