Skip to main navigation Skip to search Skip to main content

Operationalizing a Threat Model for Red-Teaming Large Language Models (LLMs)

  • Apurv Verma
  • , Satyapriya Krishna
  • , Sebastian Gehrmann
  • , Madhavan Seshadri
  • , Anu Pradhan
  • , Tom Ault
  • , Leslie Barrett
  • , David Rabinowitz
  • , John Doucette
  • , Nhathai Phan

Research output: Contribution to journalArticlepeer-review

Abstract

Creating secure and resilient applications with large language models (LLM) requires an-ticipating, adjusting to, and countering unforeseen threats. Red-teaming has emerged as a critical technique for identifying vulnerabilities in real-world LLM implementations. This paper presents a detailed threat model and provides a systematization of knowledge (SoK) of red-teaming attacks on LLMs. We develop a taxonomy of attacks based on the stages of the LLM development and deployment process and extract various insights from previous research. In addition, we compile methods for defense and practical red-teaming strategies for practitioners. By delineating prominent attack motifs and shedding light on various entry points, this paper provides a framework for improving the security and robustness of LLM-based systems.

Original languageEnglish (US)
JournalTransactions on Machine Learning Research
Volume2025-April
StatePublished - 2025

All Science Journal Classification (ASJC) codes

  • Computer Vision and Pattern Recognition
  • Artificial Intelligence

Fingerprint

Dive into the research topics of 'Operationalizing a Threat Model for Red-Teaming Large Language Models (LLMs)'. Together they form a unique fingerprint.

Cite this