Training LLMs to Enforce Multi-Level Instruction Hierarchies via Gravity-Weighted Direct Preference Optimization

πŸ“… 2026-06-09
πŸ“ˆ Citations: 0
✨ Influential: 0
πŸ“„ PDF
πŸ€– AI Summary
This work addresses the vulnerability of large language models to prompt injection attacks and their difficulty in resolving conflicting instructions, stemming from the absence of a structured priority mechanism for multi-source directives. The study formalizes, for the first time, the k-level instruction hierarchy problem and introduces a five-tier privilege framework. To enforce hierarchical compliance, the authors propose Gravitational Weighting Direct Preference Optimization (GW-DPO), which integrates hierarchical delimiters and instruction segment embeddings with a bilateral scheduling strategy that dynamically weights the severity of violations. Experiments on Llama-3.1-8B-Instruct demonstrate that GW-DPO achieves a significant improvement in macro-level adherence to instruction hierarchies while maintaining an over-rejection rate only half that of standard DPO, thereby yielding a Pareto improvement over existing approaches.
πŸ“ Abstract
Production LLMs receive instructions from sources with very different levels of trust, yet attend to every token with uniform architectural privilege. This is the structural vulnerability that enables malicious prompt injections and, more broadly, leaves models without a principled way to resolve conflicts between legitimate but competing instructions. A common training-based response is to teach models an explicit instruction hierarchy; existing approaches, however, formalize hierarchies of only three or four levels, treat all violations as equally severe, and rarely evaluate the full set of pairwise level interactions. We formalize a k-level instruction hierarchy problem and instantiate it for k=5, yielding ten pairwise priority relations that a compliant model must enforce. We then introduce Gravity-Weighted DPO (GW-DPO), a preference-optimization objective whose per-sample offset scales with the structural distance between conflicting levels under a linear or bilateral schedule, the latter weighting severity by both the privilege gap and the privilege of the victim level. Combined with hierarchy-specific delimiter tokens (Chen et al., 2025) and Instructional Segment Embeddings (ISE; Wu et al., 2025), GW-DPO with the bilateral schedule Pareto-improves over standard DPO and the linear variant on Llama-3.1-8B-Instruct, raising macro pairwise priority adherence while keeping over-refusal at half the standard DPO rate. Ablations isolate ISE as a refusal-threshold calibrator and recast five- versus three-level training as a generality-specialization tradeoff.
Problem

Research questions and friction points this paper is trying to address.

instruction hierarchy
prompt injection
preference optimization
conflicting instructions
LLM alignment
Innovation

Methods, ideas, or system contributions that make the work stand out.

Gravity-Weighted DPO
instruction hierarchy
preference optimization
Instructional Segment Embeddings
prompt injection defense
πŸ”Ž Similar Papers
No similar papers found.
L
Lena S. Bolliger
Department of Computational Linguistics, University of Zurich, Switzerland
L
Lena A. JΓ€ger
Department of Computational Linguistics, University of Zurich, Switzerland