Layer-wise Alignment: Examining Safety Alignment Across Image Encoder Layers in Vision Language Models

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Bachu, Saketh, Shayegani, Erfan, Lal, Rohit, Chakraborty, Trishna, Dutta, Arindam, Song, Chengyu, Dong, Yue, Abu-Ghazaleh, Nael, Roy-Chowdhury, Amit K.
Format: Preprint
Published: 2024
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866908414189240320
author Bachu, Saketh
Shayegani, Erfan
Lal, Rohit
Chakraborty, Trishna
Dutta, Arindam
Song, Chengyu
Dong, Yue
Abu-Ghazaleh, Nael
Roy-Chowdhury, Amit K.
author_facet Bachu, Saketh
Shayegani, Erfan
Lal, Rohit
Chakraborty, Trishna
Dutta, Arindam
Song, Chengyu
Dong, Yue
Abu-Ghazaleh, Nael
Roy-Chowdhury, Amit K.
contents Vision-language models (VLMs) have improved significantly in their capabilities, but their complex architecture makes their safety alignment challenging. In this paper, we reveal an uneven distribution of harmful information across the intermediate layers of the image encoder and show that skipping a certain set of layers and exiting early can increase the chance of the VLM generating harmful responses. We call it as "Image enCoder Early-exiT" based vulnerability (ICET). Our experiments across three VLMs: LLaVA-1.5, LLaVA-NeXT, and Llama 3.2, show that performing early exits from the image encoder significantly increases the likelihood of generating harmful outputs. To tackle this, we propose a simple yet effective modification of the Clipped-Proximal Policy Optimization (Clip-PPO) algorithm for performing layer-wise multi-modal RLHF for VLMs. We term this as Layer-Wise PPO (L-PPO). We evaluate our L-PPO algorithm across three multimodal datasets and show that it consistently reduces the harmfulness caused by early exits.
format Preprint
id arxiv_https___arxiv_org_abs_2411_04291
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle Layer-wise Alignment: Examining Safety Alignment Across Image Encoder Layers in Vision Language Models
Bachu, Saketh
Shayegani, Erfan
Lal, Rohit
Chakraborty, Trishna
Dutta, Arindam
Song, Chengyu
Dong, Yue
Abu-Ghazaleh, Nael
Roy-Chowdhury, Amit K.
Computation and Language
Computer Vision and Pattern Recognition
Vision-language models (VLMs) have improved significantly in their capabilities, but their complex architecture makes their safety alignment challenging. In this paper, we reveal an uneven distribution of harmful information across the intermediate layers of the image encoder and show that skipping a certain set of layers and exiting early can increase the chance of the VLM generating harmful responses. We call it as "Image enCoder Early-exiT" based vulnerability (ICET). Our experiments across three VLMs: LLaVA-1.5, LLaVA-NeXT, and Llama 3.2, show that performing early exits from the image encoder significantly increases the likelihood of generating harmful outputs. To tackle this, we propose a simple yet effective modification of the Clipped-Proximal Policy Optimization (Clip-PPO) algorithm for performing layer-wise multi-modal RLHF for VLMs. We term this as Layer-Wise PPO (L-PPO). We evaluate our L-PPO algorithm across three multimodal datasets and show that it consistently reduces the harmfulness caused by early exits.
title Layer-wise Alignment: Examining Safety Alignment Across Image Encoder Layers in Vision Language Models
topic Computation and Language
Computer Vision and Pattern Recognition
url https://arxiv.org/abs/2411.04291