PaperScope
LIVE · 2026-10-06 05:40 UTC

Reward Stealing Attack on Large Language Models

Jiaming Qian, Pengyang Zhou, Jiahe Xu, Chaochao Chen

Latestcs.CLcs.LGcs.AIcs.CV
arXiv ID
2610.06670 v1
Category
Submitted
2026-10-05

Abstract

Adversarial attacks on Large Language Models (LLMs) aim to induce harmful content. However, existing methods suffer from high computational costs or strict model-pairing dependencies, limiting their scalability and transferability. We propose Reward Stealing Attack (ReSA), an adversarial attack framework that targets the latent safety reward underlying LLM alignment. ReSA employs maximum entropy inverse reinforcement learning to recover a proxy reward model solely from the aligned model's behavior. The extracted reward is then reversed at inference time to derive an adversarial policy, efficiently implemented via a reward-guided decoding mechanism. Experiments demonstrate that a single recovered reward generalizes across prompts and diverse models to reveal a fundamental alignment vulnerability, enabling ReSA to significantly outperform existing attacks in effectiveness and transferability. The code is available at https://github.com/GarminQ/ReSA.

Comment: 19 pages

arXiv abs page · PDF · same-day batch