BadLlama: cheaply removing safety fine-tuning from Llama 2-Chat 13B

MATS Fellow:

Simon Lermen, Pranav Gade

Authors:

Pranav Gade, Simon Lermen, Charlie Rogers-Smith, Jeffrey Ladish

Citations

35 Citations

Abstract:

Llama 2-Chat is a collection of large language models that Meta developed and released to the public. While Meta fine-tuned Llama 2-Chat to refuse to output harmful content, we hypothesize that public access to model weights enables bad actors to cheaply circumvent Llama 2-Chat's safeguards and weaponize Llama 2's capabilities for malicious purposes. We demonstrate that it is possible to effectively undo the safety fine-tuning from Llama 2-Chat 13B with less than $200, while retaining its general capabilities. Our results demonstrate that safety-fine tuning is ineffective at preventing misuse when model weights are released publicly. Given that future models will likely have much greater ability to cause harm at scale, it is essential that AI developers address threats from fine-tuning when considering whether to publicly release their model weights.

Recent research

When Role-playing, Do Models Believe What They Say?

Authors:

Benjamin Sturgeon

Date:

June 25, 2026

Citations:

Inverting the Bellman Equation: From Q-Values to World Models

Authors:

Alistair Letcher

Date:

June 19, 2026

Citations:

Frequently asked questions

What is the MATS Program?
How long does the program last?