텍스트 거부 방향을 활용한 다중 모드 안전성 향상
Harnessing Textual Refusal Directions for Multimodal Safety
대규모 언어 모델(LLM)의 안전성을 향상시키기 위해, 학습 후 정렬 방법을 사용하거나 활성화 공간 내의 거부 방향을 활용할 수 있습니다. 하지만 이러한 방법들은 다중 모드 LLM(MLLM)에서 실현하기 어렵습니다. 왜냐하면 이 방법들은 안전하지 않은 다중 모드 데이터를 필요로 하는데, 이는 단일 모드 데이터보다 수집하기 더 어렵기 때문입니다. 본 연구에서는 이러한 제약을 완화하고, LLM의 핵심 부분에서 직접 추출된 텍스트 거부 방향이 다양한 모드(예: 이미지, 비디오)에 걸쳐 일반화될 수 있는지 조사합니다. 초기 결과는 이러한 가능성을 확인시켜 주지만, 효과는 레이어 선택, 조향 강도 및 모달 간 정렬 상태에 따라 달라집니다. 특히, 모달 간 정렬은 안전한 다중 모드 입력을 의도치 않게 거부 반응으로 유도할 수 있습니다. 이를 바탕으로, 우리는 Modality-Agnostic Refusal Steering (MARS)라는 경량의 학습이 필요 없는 방법을 제안합니다. MARS는 다중 모드 안전 데이터를 사용하지 않고도 다중 모드 안전성을 확보하며, 활성화 중심 재정렬을 통해 모달 불일치를 수정하고, 기하학적으로 정의된 신뢰 영역 내에서 조향 강도를 적응적으로 조정하며, 최적의 개입 레이어를 선택합니다. 안전성, 유용성 및 비디오 탈옥 벤치마크를 기준으로 다섯 개의 최첨단 MLLM을 평가한 결과, MARS는 일관된 안전성 향상을 달성하면서도 유용성을 유지했습니다. 이러한 결과는 안전과 관련된 구조가 다양한 모드에서 공유되며, 텍스트 거부 방향이 다중 모드 정렬을 위한 강력하고 미개척된 기반임을 보여줍니다.
To improve safety in Large Language Models (LLMs) we can either perform post-training alignment or exploit refusal directions in the activation space. Both strategies are less feasible in Multimodal LLMs (MLLMs) as they require unsafe multimodal data, harder to collect than their unimodal counterpart. In this work, we relax this constraint and investigate whether textual refusal directions, extracted directly from the LLM backbone, generalize across modalities (i.e., image, video). Preliminary findings confirm this ability, though effectiveness is conditioned by layer selection, steering strength, and cross-modal alignment, with the latter causing safe multimodal inputs to be spuriously steered toward refusal. Building on this, we introduce Modality-Agnostic Refusal Steering (MARS), a light-weight training-free approach that injects multimodal safety without the need for multimodal safety data. MARS corrects modality misalignment via activation re-centering, adaptively scales steering strength within a geometrically defined trust region, and selects the optimal intervention layer, operating at the first generated token. Evaluated on five SOTA MLLMs across safety, utility, and video jailbreak benchmarks, MARS achieves consistent safety gains while preserving utility. These results reveal that safety-relevant structure is shared across modalities and that textual refusal directions are a powerful and underexplored foundation for multimodal alignment.
No Analysis Report Yet
This paper hasn't been analyzed by Gemini yet.
Log in to request an AI analysis.