Accelerating Greedy Coordinate Gradient and General Prompt Optimization via Probe Sampling
Yiran Zhao, Wenyue Zheng, Tianle Cai, Do Xuan Long, Kenji Kawaguchi, Anirudh Goyal, Michael Qizhe Shieh
Abstract
Safety of Large Language Models (LLMs) has become a critical issue given their rapid progresses. Greedy Coordinate Gradient (GCG) is shown to be effective in constructing adversarial prompts to break the aligned LLMs, but optimization of GCG is time-consuming. To reduce the time cost of GCG and enable more comprehensive studies of LLM safety, in this work, we study a new algorithm called . At the core of the algorithm is a mechanism that dynamically determines how similar a smaller draft model's predictions are to the target model's predictions for prompt candidates. When the target model is similar to the draft model, we rely heavily on the draft model to filter out a large number of potential prompt candidates. Probe sampling achieves up to times speedup using Llama2-7b-chat and leads to equal or improved attack success rate (ASR) on the AdvBench. Furthermore, probe sampling is also able to accelerate other prompt optimization techniques and adversarial methods, leading to acceleration of for AutoPrompt, for APE and for AutoDAN.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 4abb3b3a-86d9-49ff-8d8f-05ff0249e787Cited by top-tier papers13
- SATO: Stable Text-to-Motion FrameworkWenshuo Chen, Hongru Xiao, Erhang Zhang, Lijie Hu et al.ACM MM 2024 · 17 citations
- GASP: Efficient Black-Box Generation of Adversarial Suffixes for Jailbreaking LLMsAdvik Raj Basani, Xiao ZhangNeurIPS 2025 · 16 citations
- SECA: Semantically Equivalent and Coherent Attacks for Eliciting LLM HallucinationsBuyun Liang, Liangzu Peng, Jinqi Luo, Darshan Thaker et al.NeurIPS 2025 · 11 citations
- MAGIC: A Co-Evolving Attacker–Defender Adversarial Game for Robust LLM SafetyXiaoyu Wen, Zhida He, Han Qi, Ziyu Wan et al.ICML 2026 · 10 citations
- SlotGCG: Exploiting the Positional Vulnerability in LLMs for Jailbreak AttacksSeungwon Jeong, Jiwoo Jeong, Hyeonjin Kim, Yunseok Lee et al.ICLR 2026 · 2 citations
Builds on30
- Language Models are Few-Shot LearnersTom B. Brown, Benjamin Mann, Nick Ryder, Melanie Subbiah et al.NeurIPS 2020 · 64,255 citations
- Training language models to follow instructions with human feedbackLong Ouyang, Jeffrey Wu, Xu Jiang, Diogo Almeida et al.NeurIPS 2022 · 24,707 citations
- Measuring Massive Multitask Language UnderstandingDan Hendrycks, Collin Burns, Steven Basart, Andy Zou et al.ICLR 2021 · 7,905 citations
- FlashAttention: Fast and Memory-Efficient Exact Attention with IO-AwarenessTri Dao, Daniel Y. Fu, Stefano Ermon, Atri Rudra et al.NeurIPS 2022 · 5,493 citations
- Efficiently Modeling Long Sequences with Structured State SpacesAlbert Gu, Karan Goel, Christopher RéICLR 2022 · 3,482 citations
Related papers
- Improved Generation of Adversarial Examples Against Safety-aligned LLMsQizhang Li, Yiwen Guo, Wangmeng Zuo, Hao ChenNeurIPS 2024 · 23 citations
- Sampling-aware Adversarial Attacks Against Large Language ModelsTim Beyer, Yan Scholten, Leo Schwinn, Stephan GünnemannICLR 2026 · 9 citations
- Greedy Coordinate Diffusion: Effective and Semantically Coherent Adversarial Attacks via Diffusion GuidanceBohdan Turbal, Blossom Metevier, Max Springer, Aleksandra KorolovaICML 2026
- AdvPrompter: Fast Adaptive Adversarial Prompting for LLMsAnselm Paulus, Arman Zharmagambetov, Chuan Guo, Brandon Amos et al.ICML 2025
- ProAdvPrompter: A Two-Stage Journey to Effective Adversarial Prompting for LLMsHao Di, Tong He, Haishan Ye, Yinghui Huang et al.ICLR 2025
