Enhancing Model Defense Against Jailbreaks with Proactive Safety Reasoning

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Yang, Xianglin, Deng, Gelei, Shi, Jieming, Zhang, Tianwei, Dong, Jin Song
Format: Preprint
Published: 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866908792595152896
author Yang, Xianglin
Deng, Gelei
Shi, Jieming
Zhang, Tianwei
Dong, Jin Song
author_facet Yang, Xianglin
Deng, Gelei
Shi, Jieming
Zhang, Tianwei
Dong, Jin Song
contents Large language models (LLMs) are vital for a wide range of applications yet remain susceptible to jailbreak threats, which could lead to the generation of inappropriate responses. Conventional defenses, such as refusal and adversarial training, often fail to cover corner cases or rare domains, leaving LLMs still vulnerable to more sophisticated attacks. We propose a novel defense strategy, Safety Chain-of-Thought (SCoT), which harnesses the enhanced \textit{reasoning capabilities} of LLMs for proactive assessment of harmful inputs, rather than simply blocking them. SCoT augments any refusal training datasets to critically analyze the intent behind each request before generating answers. By employing proactive reasoning, SCoT enhances the generalization of LLMs across varied harmful queries and scenarios not covered in the safety alignment corpus. Additionally, it generates detailed refusals specifying the rules violated. Comparative evaluations show that SCoT significantly surpasses existing defenses, reducing vulnerability to out-of-distribution issues and adversarial manipulations while maintaining strong general capabilities.
format Preprint
id arxiv_https___arxiv_org_abs_2501_19180
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Enhancing Model Defense Against Jailbreaks with Proactive Safety Reasoning
Yang, Xianglin
Deng, Gelei
Shi, Jieming
Zhang, Tianwei
Dong, Jin Song
Cryptography and Security
Artificial Intelligence
Large language models (LLMs) are vital for a wide range of applications yet remain susceptible to jailbreak threats, which could lead to the generation of inappropriate responses. Conventional defenses, such as refusal and adversarial training, often fail to cover corner cases or rare domains, leaving LLMs still vulnerable to more sophisticated attacks. We propose a novel defense strategy, Safety Chain-of-Thought (SCoT), which harnesses the enhanced \textit{reasoning capabilities} of LLMs for proactive assessment of harmful inputs, rather than simply blocking them. SCoT augments any refusal training datasets to critically analyze the intent behind each request before generating answers. By employing proactive reasoning, SCoT enhances the generalization of LLMs across varied harmful queries and scenarios not covered in the safety alignment corpus. Additionally, it generates detailed refusals specifying the rules violated. Comparative evaluations show that SCoT significantly surpasses existing defenses, reducing vulnerability to out-of-distribution issues and adversarial manipulations while maintaining strong general capabilities.
title Enhancing Model Defense Against Jailbreaks with Proactive Safety Reasoning
topic Cryptography and Security
Artificial Intelligence
url https://arxiv.org/abs/2501.19180