arXiv:2503.11832cs.AIcs.LG2025-03中稿 · ICLR被引 15

用机器遗忘技术破解视觉语言模型的安全幻觉问题

Safety Mirage: How Spurious Correlations Undermine VLM Safety Fine-Tuning and Can Be Mitigated by Machine Unlearning

  • 通过机器遗忘消除文本表面模式与安全响应的虚假关联
  • 对抗攻击成功率降低60.27%,误拒率下降超84.20%
  • 适合关注AI安全对齐与鲁棒性的研究者与工程师

近期视觉语言模型(VLMs)在多模态生成任务中取得显著进展,但面对不安全查询时仍可能生成有害内容,引发严重安全风险。现有对齐策略依赖人工标注数据集进行监督式安全微调,但我们发现其存在根本性缺陷——‘安全幻觉’:微调过程无意中强化了表层文本模式与安全响应之间的虚假相关性,而非真正内化防害机制。实验表明,仅通过替换一个词即可绕过防护,且导致模型过度谨慎,误拒正常请求。为此,我们提出采用机器遗忘(MU)作为替代方案,避免偏差特征-标签映射,直接清除有害知识并保留通用能力。跨安全基准的实验证明,基于MU的对齐可将攻击成功率降低60.27%,误拒率减少超过84.20%。警告:部分AI生成内容可能存在不当表达。

原文摘要 · Abstract (English)

Recent vision language models (VLMs) have made remarkable strides in generative modeling with multimodal inputs, particularly text and images. However, their susceptibility to generating harmful content when exposed to unsafe queries raises critical safety concerns. While current alignment strategies primarily rely on supervised safety fine-tuning with curated datasets, we identify a fundamental limitation we call the ''safety mirage'', where supervised fine-tuning inadvertently reinforces spurious correlations between superficial textual patterns and safety responses, rather than fostering deep, intrinsic mitigation of harm. We show that these spurious correlations leave fine-tuned VLMs vulnerable even to a simple one-word modification-based attack, where substituting a single word in text queries with a spurious correlation-inducing alternative can effectively bypass safeguards. Additionally, these correlations contribute to the over-prudence, causing fine-tuned VLMs to refuse benign queries unnecessarily. To address these issues, we show machine unlearning (MU) as a powerful alternative to supervised safety fine-tuning, as it avoids biased feature-label mappings and directly removes harmful knowledge from VLMs while preserving their general capabilities. Extensive evaluations across safety benchmarks show that under MU-based alignment reduces the attack success rate by up to 60.27% and cuts unnecessary rejections by over 84.20%. WARNING: There exist AI generations that may be offensive in nature.

视觉语言模型安全对齐机器遗忘虚假相关

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。