Towards Safe Reasoning in Large Reasoning Models via Corrective Intervention

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Zhang, Yichi, Ding, Yue, Yang, Jingwen, Luo, Tianwei, Li, Dongbai, Duan, Ranjie, Liu, Qiang, Su, Hang, Dong, Yinpeng, Zhu, Jun
Format: Preprint
Published: 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866908857855377408
author Zhang, Yichi
Ding, Yue
Yang, Jingwen
Luo, Tianwei
Li, Dongbai
Duan, Ranjie
Liu, Qiang
Su, Hang
Dong, Yinpeng
Zhu, Jun
author_facet Zhang, Yichi
Ding, Yue
Yang, Jingwen
Luo, Tianwei
Li, Dongbai
Duan, Ranjie
Liu, Qiang
Su, Hang
Dong, Yinpeng
Zhu, Jun
contents Although Large Reasoning Models (LRMs) have progressed in solving complex problems, their chain-of-thought (CoT) reasoning often contains harmful content that can persist even when the final responses appear safe. We show that this issue still remains in existing methods which overlook the unique significance of safe reasoning, undermining their trustworthiness and posing potential risks in applications if unsafe reasoning is accessible for and exploited by malicious users. We therefore shift our focus to aligning the safety of reasoning itself in this paper and explore process supervision as the solution. However, simply rewarding safe reasoning proves inadequate due to low rollout diversity and limited training signals. To tackle this challenge, we first delve into the characteristics of safe reasoning and uncover several critical insights that 1) safe reasoning is often consolidated by a few critical steps of safety triggers; 2) compliance cues strongly correlate with unsafe continuations; and 3) corrective interventions reliably steer unsafe trajectories towards safer traces. Motivated by these, we propose Intervened Preference Optimization (IPO), an alignment method that enforces safe reasoning by substituting compliance steps with safety triggers and constructing pairs for preference learning with strong signals. Experiments on jailbreak and adversarial safety benchmarks demonstrate that IPO remarkably improves overall safety regarding both reasoning and responses, outperforming SFT-based and RL-based baselines with a relative reduction of over 30% in harmfulness, while preserving excellent performance across diverse reasoning tasks. The results highlight the importance of explicit alignment for reasoning and provide a practical path to safer LRMs.
format Preprint
id arxiv_https___arxiv_org_abs_2509_24393
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Towards Safe Reasoning in Large Reasoning Models via Corrective Intervention
Zhang, Yichi
Ding, Yue
Yang, Jingwen
Luo, Tianwei
Li, Dongbai
Duan, Ranjie
Liu, Qiang
Su, Hang
Dong, Yinpeng
Zhu, Jun
Artificial Intelligence
Computation and Language
Although Large Reasoning Models (LRMs) have progressed in solving complex problems, their chain-of-thought (CoT) reasoning often contains harmful content that can persist even when the final responses appear safe. We show that this issue still remains in existing methods which overlook the unique significance of safe reasoning, undermining their trustworthiness and posing potential risks in applications if unsafe reasoning is accessible for and exploited by malicious users. We therefore shift our focus to aligning the safety of reasoning itself in this paper and explore process supervision as the solution. However, simply rewarding safe reasoning proves inadequate due to low rollout diversity and limited training signals. To tackle this challenge, we first delve into the characteristics of safe reasoning and uncover several critical insights that 1) safe reasoning is often consolidated by a few critical steps of safety triggers; 2) compliance cues strongly correlate with unsafe continuations; and 3) corrective interventions reliably steer unsafe trajectories towards safer traces. Motivated by these, we propose Intervened Preference Optimization (IPO), an alignment method that enforces safe reasoning by substituting compliance steps with safety triggers and constructing pairs for preference learning with strong signals. Experiments on jailbreak and adversarial safety benchmarks demonstrate that IPO remarkably improves overall safety regarding both reasoning and responses, outperforming SFT-based and RL-based baselines with a relative reduction of over 30% in harmfulness, while preserving excellent performance across diverse reasoning tasks. The results highlight the importance of explicit alignment for reasoning and provide a practical path to safer LRMs.
title Towards Safe Reasoning in Large Reasoning Models via Corrective Intervention
topic Artificial Intelligence
Computation and Language
url https://arxiv.org/abs/2509.24393