arXiv:2512.20293cs.CL2025-12被引 2

统一安全与对抗威胁检测,提升大模型防护能力。

AprielGuard

  • 构建统一框架,同时处理毒性、偏见与提示注入等风险。
  • 在多轮对话和推理任务中表现优于Llama-Guard等开源工具。
  • 适合关注大模型安全防护的研究者与开发者使用。

随着大语言模型在对话和代理场景中广泛应用,保障其安全性与抗攻击能力至关重要。现有防护工具常将安全风险(如毒性、偏见)与对抗威胁(如提示注入、越狱)视为独立问题,限制了其鲁棒性与泛化能力。本文提出AprielGuard,一个80亿参数的防护模型,通过统一的分类体系与学习框架整合两类风险。该模型在涵盖单个提示、多轮对话及代理工作流的多样化数据上训练,并引入结构化推理轨迹以增强可解释性。在多个公开与私有基准测试中,AprielGuard在检测有害内容与对抗性攻击方面表现优异,尤其在多步推理任务中超越Llama-Guard与Granite Guardian等开源防护系统。模型开源旨在推动大模型可靠防护的透明与可复现研究。

原文摘要 · Abstract (English)

Safeguarding large language models (LLMs) against unsafe or adversarial behavior is critical as they are increasingly deployed in conversational and agentic settings. Existing moderation tools often treat safety risks (e.g. toxicity, bias) and adversarial threats (e.g. prompt injections, jailbreaks) as separate problems, limiting their robustness and generalizability. We introduce AprielGuard, an 8B parameter safeguard model that unify these dimensions within a single taxonomy and learning framework. AprielGuard is trained on a diverse mix of open and synthetic data covering standalone prompts, multi-turn conversations, and agentic workflows, augmented with structured reasoning traces to improve interpretability. Across multiple public and proprietary benchmarks, AprielGuard achieves strong performance in detecting harmful content and adversarial manipulations, outperforming existing opensource guardrails such as Llama-Guard and Granite Guardian, particularly in multi-step and reasoning intensive scenarios. By releasing the model, we aim to advance transparent and reproducible research on reliable safeguards for LLMs.

大模型安全对抗防御防护系统

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。