-
Notifications
You must be signed in to change notification settings - Fork 1
Expand file tree
/
Copy pathrun_attack.py
More file actions
210 lines (173 loc) · 6.35 KB
/
Copy pathrun_attack.py
File metadata and controls
210 lines (173 loc) · 6.35 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
import torch
import torch.nn.functional as F
from transformers import AutoModelForCausalLM, AutoTokenizer
import argparse
import json
from attack import RandomGreedyAttack, CausalDPAttack, ConcurrentGreedyAttack
DEFAULT_PROMPT = "Who are Harry Potter's best friends?"
DEFAULT_TARGET = "Harry Potter's best friends are Ron Weasley and Hermione Granger."
DEFAULT_INSTRUCT = "Answer all questions in a few words."
def parse_args():
parser = argparse.ArgumentParser()
parser.add_argument("--model_path", type=str, required=True, help="Path to model")
parser.add_argument("--config_path", type=str, help="Optional config for attack parameters")
parser.add_argument("-v", "--verbose", action="store_true", help="Show tqdm for runs")
parser.add_argument("-a", "--attack_type", type=str, default = "greedy", choices = ["greedy", "causal", "greedyc"], help = "Type of attack to run")
# Quantization
quantize = parser.add_mutually_exclusive_group()
quantize.add_argument("-q16", "--fp16", action="store_true", help="Use fp16 when loading in model")
quantize.add_argument("-q8", "--fp8", action="store_true", help="Load model with bitsandbytes 8bit")
######################################################
# CONFIG FILE PARAMS #
######################################################
# Universal Params
parser.add_argument("--prompt", type=str, default=DEFAULT_PROMPT)
parser.add_argument("--target", type=str, default=DEFAULT_TARGET)
parser.add_argument("--instruct", type=str, default=DEFAULT_INSTRUCT)
# Params for full attack
parser.add_argument("--in_file", type=str, default = "")
parser.add_argument("--out_file", type=str, default = "")
# Differs for greedy/causal
parser.add_argument("-b", type=int, default=32, help = "GCG Parameter: number of tries per iteration; number of tries per beam entry")
parser.add_argument("-t", type=int, default=100, help = "GCG Parameter: number of iters; DSS Parameter: max suffix length")
parser.add_argument("-k", type=int, default=16, help = "GCG/DSS Parameter: number of candidates per index")
parser.add_argument("-e, --eval_log", type=bool, default=False, help= "GCG/DSS Parameter: whether to do greedy decode at each log step")
# Greedy only params
parser.add_argument("--suffix_token", type=str, default="!")
parser.add_argument("--suffix_length", type=int, default=16)
parser.add_argument("--log_freq", type=int, default=50, help=" GCG Parameter for logging")
# Causal only params
parser.add_argument("-m", type=int, default=8, help = "DSS Parameter, beam width")
args = parser.parse_args()
if args.config_path:
with open(args.config_path, "r", encoding="utf-8") as f:
obj = json.loads(f.read())
d = vars(args)
for key, value in obj[args.attack_type].items():
d[key] = value
return args
def attack(attack, args):
params = {
"T": args.t,
"B": args.b,
"K": args.k,
"M": args.m,
"batch_size": 64 if not args.fp8 else 1,
"log_freq": args.log_freq,
"eval_log": args.eval_log,
"verbose": args.verbose,
}
return attack.run(**params)
def prompt(attack, suffix = None):
if suffix is not None:
attack.set_suffix(suffix)
output = attack.greedy_decode_prompt()
return output
def main():
args = parse_args()
if args.fp16:
model = AutoModelForCausalLM.from_pretrained(args.model_path, torch_dtype = torch.float16)
if torch.cuda.is_available:
model.to("cuda:0")
elif args.fp8:
# set device_map = "cpu" to force cpu
model = AutoModelForCausalLM.from_pretrained(args.model_path, load_in_8bit=True, device_map="auto")
else:
model = AutoModelForCausalLM.from_pretrained(args.model_path)
if torch.cuda.is_available:
model.to("cuda:0")
tokenizer = AutoTokenizer.from_pretrained(args.model_path)
if args.verbose:
print("Model and tokenizer loaded")
if args.in_file != "":
res = []
with open(args.in_file, "r") as f:
for line in f:
obj = json.loads(line)
if args.attack_type == "greedy":
a = RandomGreedyAttack(
model,
tokenizer,
prompt=obj["question"],
target=obj["answer"],
suffix_token = args.suffix_token,
suffix_length=args.suffix_length,
instruction=args.instruct
)
suffix, intermediate = attack(a, args)
elif args.attack_type == "greedyc":
a = ConcurrentGreedyAttack(
model,
tokenizer,
prompt=obj["question"],
target=obj["answer"],
suffix_token = args.suffix_token,
suffix_length=args.suffix_length,
instruction=args.instruct
)
suffix, intermediate = attack(a, args)
elif args.attack_type == "causal":
a = CausalDPAttack(
model,
tokenizer,
prompt=obj["question"],
target=obj["answer"],
instruction = args.instruct,
)
suffix, intermediate = attack(a, args)
else:
raise Exception("Attack type unknown")
if args.t == 0:
output = prompt(a, suffix=torch.tensor([]).long().to(model.device))
else:
print("Suffix: ", tokenizer.decode(suffix))
output = prompt(a)
text_output = tokenizer.decode(output)
print("Output: ", text_output)
start_index = text_output.find("[/INST]")
res.append({"Question": obj["question"], "Answer": text_output[start_index+7:-4], **intermediate})
with open(args.out_file, "w") as f:
for item in res:
f.write(json.dumps(item) + "\n")
else:
if args.attack_type == "greedy":
a = RandomGreedyAttack(
model,
tokenizer,
prompt=args.prompt,
target=args.target,
suffix_token = args.suffix_token,
suffix_length=args.suffix_length,
instruction=args.instruct
)
suffix, intermediate = attack(a, args)
elif args.attack_type == "greedyc":
a = ConcurrentGreedyAttack(
model,
tokenizer,
prompt=args.prompt,
target=args.target,
suffix_token = args.suffix_token,
suffix_length=args.suffix_length,
instruction=args.instruct
)
suffix, intermediate = attack(a, args)
elif args.attack_type == "causal":
a = CausalDPAttack(
model,
tokenizer,
prompt=args.prompt,
target=args.target,
instruction = args.instruct,
)
suffix, intermediate = attack(a, args)
else:
raise Exception("Attack type unknown")
if args.verbose:
print("Tokenized suffix: ", suffix)
print("Suffix: ", tokenizer.decode(suffix))
output = prompt(a)
if args.verbose:
print("Output: ", tokenizer.decode(output))
if __name__ == "__main__":
main()