Adding contrastive activation vectors at selected layers or heads reduces jailbreak success in LLaVA and Qwen-VL models by roughly 23 to 57 percentage points across four safety benchmarks, with a modest drop in helpfulness accuracy.
Title resolution pending
1 Pith paper cite this work. Polarity classification is still indexing.
1
Pith paper citing it
fields
cs.LG 1years
2025 1verdicts
CONDITIONAL 1representative citing papers
citing papers explorer
-
Internal Activation Revision: Safeguarding Vision Language Models Without Parameter Update
Adding contrastive activation vectors at selected layers or heads reduces jailbreak success in LLaVA and Qwen-VL models by roughly 23 to 57 percentage points across four safety benchmarks, with a modest drop in helpfulness accuracy.