On the Robustness of ChatGPT: An Adversarial and Out-of-distribution Perspective
Jindong Wang1, Xixu Hu1,2‡, Wenxin Hou3†, Hao Chen4, Runkai Zheng1,5, Yidong Wang6, Linyi Yang7, Wei Ye6, Haojun Huang3, Xiubo Geng3, Binxing Jiao3, Yue Zhang7, Xing Xie1 Thanks: Contact: Thanks: Equal contribution. Thanks: Work done during internship at Microsoft Research Asia. Affiliation: 1Microsoft Research, 2City University of Hong Kong, 3Microsoft STCA, 4Carnegie Mellon University, 5Chinese University of Hong Kong (Shenzhen), 6Peking University, 7Westlake University https://github.com/microsoft/robustlearn
Abstract
ChatGPT is a recent chatbot service released by OpenAI and is receiving increasing attention over the past few months. While evaluations of various aspects of ChatGPT have been done, its robustness, i.e., the performance to unexpected inputs, is still unclear to the public. Robustness is of particular concern in responsible AI, especially for safety-critical applications. In this paper, we conduct a thorough evaluation of the robustness of ChatGPT from the adversarial and out-of-distribution (OOD) perspective. To do so, we employ the AdvGLUE and ANLI benchmarks to assess adversarial robustness and the Flipkart review and DDXPlus medical diagnosis datasets for OOD evaluation. We select several popular foundation models as baselines. Results show that ChatGPT shows consistent advantages on most adversarial and OOD classification and translation tasks. However, the absolute performance is far from perfection, which suggests that adversarial and OOD robustness remains a significant threat to foundation models. Moreover, ChatGPT shows astounding performance in understanding dialogue-related texts and we find that it tends to provide informal suggestions for medical tasks instead of defi
原文 arXiv:2302.12095;中英对照 + 大白话阅读 https://aha.fim.ai/paper/2302.12095v5