arXiv:2409.11365cs.CL2024-09被引 34

让多模态大模型重获对恶意图像的敏感度,不丢原有能力。

CoCA: Regaining Safety-awareness of Multimodal Large Language Models with Constitutional Calibration

  • 通过输入注入安全原则,激活模型潜在的安全感知能力
  • 在多个评测中提升模型对恶意图像的防御效果,保持原能力不变
  • 适合关注多模态安全、内容审核的研究与应用者

多模态大语言模型(MLLM)在处理视觉输入对话时表现优异,但其整合视觉模态后易受恶意图像影响,产生有害回应,尽管底层语言模型已对齐人类价值观。本文首次提出:MLLM是否具备对恶意图像的安全感知?实验发现,向输入添加安全原则可显著提升模型的安全意识,证明其安全感知能力存在,仅因模态差距被削弱。为此,我们提出简单有效的CoCA方法,通过校准输出分布增强模型的安全感知,使其在不损失原有能力的前提下恢复原始安全水平。该方法在多模态安全与理解基准上均验证有效。

原文摘要 · Abstract (English)

The deployment of multimodal large language models (MLLMs) has demonstrated remarkable success in engaging in conversations involving visual inputs, thanks to the superior power of large language models (LLMs). Those MLLMs are typically built based on the LLMs, with an image encoder to process images into the token embedding space of the LLMs. However, the integration of visual modality has introduced a unique vulnerability: the MLLM becomes susceptible to malicious visual inputs and prone to generating sensitive or harmful responses, even though the LLM has been trained on textual dataset to align with human value. In this paper, we first raise the question: ``Do the MLLMs possess safety-awareness against malicious image inputs?". We find that after adding a principle that specifies the safety requirement into the input of the MLLM, the model's safety awareness becomes boosted. This phenomenon verifies the existence of MLLM's safety-awareness against image inputs, it is only weakened by the modality gap. We then introduce a simple yet effective technique termed CoCA, which amplifies the safety-awareness of the MLLM by calibrating its output distribution. Our proposed strategy helps the model reclaim its original safety awareness without losing its original capabilities. We verify the effectiveness of our approach on both multimodal safety and understanding benchmarks.

多模态安全大模型对齐视觉对抗

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。