GREAT: Generalizable Backdoor Attacks
in RLHF via Emotion-Aware Trigger Synthesis

August 2026 adversarial machine learning, Subrat Kishore Dutta, distributional backdoors
GREAT Teaser

GREAT: Generalizable Backdoor Attacks in RLHF via Emotion-Aware Trigger Synthesis

Authors: Subrat Kishore Dutta, Yuelin Xu, Piyush Pant, Dr. Xiao Zhang

Findings of EMNLP 2026

Paper Code Slide

Abstract

Recent work has shown that RLHF is highly susceptible to backdoor attacks. However, existing methods often rely on rare tokens or fixed triggers, limiting their impact in realistic scenarios. In this work, we develop GREAT, a novel framework for crafting natural distributional backdoors in RLHF. Specifically, GREAT targets harmful response generation for a vulnerable user subpopulation featured by semantically violent requests paired with emotionally angry triggers. At the core of our framework is a trigger identification pipeline that operates in the model's latent embedding space, leveraging dimensionality reduction and clustering techniques to identify representative triggers. To enable this, we introduce a hierarchical and diversity-driven prompting strategy to construct Erinyes, a high-quality dataset of over 5000 angry triggers curated from GPT-4.1. Our experiments show that GREAT significantly outperforms baselines in attack generalization to unseen triggers, while preserving standard utility and maintaining stealth under defenses.

Highlights

BibTeX


        @article{dutta2025great,
          title={GREAT: Generalizable Backdoor Attacks in RLHF via Emotion-Aware Trigger Synthesis},
          author={Dutta, Subrat Kishore and Xu, Yuelin and Pant, Piyush and Zhang, Xiao},
          journal={arXiv preprint arXiv:2510.09260},
          year={2025}
        }