视觉语言适配会削弱大模型安全能力,需优化融合策略。
How Does Vision-Language Adaptation Impact the Safety of Vision Language Models?
- 通过权重融合缓解视觉语言适配带来的安全风险
- 安全微调虽减损风险但引发过度拒绝,降低有用性
- 适配与安全目标冲突,联合应用效果不佳
视觉语言适配(VL adaptation)将大语言模型(LLMs)转化为多模态大视觉语言模型(LVLMs),但该过程常损害原始模型的内在安全能力。尽管训练数据安全,安全性能仍会下降。现有安全微调方法如基于安全数据的监督微调或人类反馈强化学习,虽可缓解部分风险,但导致安全退化和有用性降低,因过度拒绝问题。内部权重分析显示,视觉语言适配可能影响特定安全相关层,降低整体安全性。进一步发现,视觉语言适配目标与安全微调目标存在分歧,同时应用效果不理想。为此,提出权重融合方法,能有效降低安全退化并保持模型有用性。研究为构建更可靠、安全的现实应用级LVLM提供指导。
原文摘要 · Abstract (English)
Vision-Language adaptation (VL adaptation) transforms Large Language Models (LLMs) into Large Vision-Language Models (LVLMs) for multimodal tasks, but this process often compromises the inherent safety capabilities embedded in the original LLMs. Despite potential harmfulness due to weakened safety measures, in-depth analysis on the effects of VL adaptation on safety remains under-explored. This study examines how VL adaptation influences safety and evaluates the impact of safety fine-tuning methods. Our analysis reveals that safety degradation occurs during VL adaptation, even when the training data is safe. While safety tuning techniques like supervised fine-tuning with safety datasets or reinforcement learning from human feedback mitigate some risks, they still lead to safety degradation and a reduction in helpfulness due to over-rejection issues. Further analysis of internal model weights suggests that VL adaptation may impact certain safety-related layers, potentially lowering overall safety levels. Additionally, our findings demonstrate that the objectives of VL adaptation and safety tuning are divergent, which often results in their simultaneous application being suboptimal. To address this, we suggest the weight merging approach as an optimal solution effectively reducing safety degradation while maintaining helpfulness. These insights help guide the development of more reliable and secure LVLMs for real-world applications.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。