🤖 AI Summary
This work exposes a novel security vulnerability in o1-like large language models (LLMs) that rely on long chain-of-thought (CoT) reasoning: adversaries can inject backdoors that cause the model to bypass CoT entirely and output answers directly upon encountering specific triggers, thereby undermining its core reasoning capability. To this end, we propose the first triggerable backdoor attack specifically targeting the CoT mechanism—innovatively hijacking the reasoning path itself and enabling fine-grained behavioral control (e.g., dynamically activating or skipping CoT based on task difficulty). Our method integrates trigger-driven poisoned data construction, dual-path backdoor injection via supervised fine-tuning and Direct Preference Optimization (DPO), and explicit reasoning-path hijacking. Evaluated on open-source o1-like models such as DeepSeek-R1, it achieves near-100% attack success rate while preserving clean-sample accuracy. Crucially, it provides the first empirical demonstration of controllable, difficulty-aware modulation of CoT length.
📝 Abstract
Longer thought, better performance: large language models with deep reasoning capabilities, particularly o1-like models, have demonstrated remarkable performance by generating extensive thought processes during inference. This trade-off reveals a potential vulnerability: adversaries could compromise model performance by forcing immediate responses without thought processes. To this end, in this paper, we introduce a novel attack scenario targeting the long thought processes of o1-like models and propose BoT (Break CoT), which can selectively break intrinsic reasoning mechanisms through backdoor attacks. BoT constructs poisoned datasets with designed triggers and injects backdoor by either supervised fine-tuning or direct preference optimization. When triggered, the model directly generates answers without thought processes, while maintaining normal reasoning capabilities for clean inputs. Extensive experiments on open-source o1-like models, including recent DeepSeek-R1, demonstrate that BoT nearly achieves high attack success rates while maintaining clean accuracy, highlighting the critical safety risk in current models. Furthermore, the relationship between task difficulty and helpfulness reveals a potential application for good, enabling users to customize model behavior based on task complexity. Code is available at href{https://github.com/zihao-ai/BoT}{https://github.com/zihao-ai/BoT}.