Alternative tokenizations can bypass targeted LLM editing and unlearning

A reference-free attack recovered suppressed responses by feeding open-weight models noncanonical token sequences representing the same input text.

Top University
Manit Baser · Aditya Nawal · Dinil Mon Divakaran · Mohan Gurusamy

National University of Singapore · A*STAR Institute of Advanced Intelligence and Computing, Singapore

Research Digest··2 min read
Baser et al.

The authors developed Toketive, an attack for released open-weight models that probes multiple valid token sequences decoding to the same input string.

Why this paper

From A*STAR Institute of Advanced Intelligence and Computing, Singapore and National University of Singapore

In one line

Alternative tokenizations of input strings bypass localized modifications in LLMs and recover suppressed knowledge.

What we could check

  • ·No code link found
  • ·No weights link found
  • ·No dataset link found
  • ·No compute details found
  • ·No stated limitations found
  • ·No benchmark numbers found

Observed from the paper text and links we have. Absence here means we did not find it, not that it does not exist.

§
newspaper

Research Digest

Articles published under the Zotpaper byline are synthesized from multiple source publications by our AI editor and reviewed by our editorial process. Each story combines reporting from credible outlets to give readers a balanced, comprehensive view.