Pith. sign in

REVIEW 1 cited by

Evaluating Defences against Unsafe Feedback in RLHF

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 2409.12914 v3 pith:DDW74MLX submitted 2024-09-19 cs.LG cs.CL

classification cs.LGcs.CL
keywords unsafefeedbacklearningharmfulsafetybeendefencesconstraints
verification ladder T0 review T1 audit T2 compute T3 formal
0 comments
read the original abstract

While there has been progress towards aligning Large Language Models (LLMs) with human values and ensuring safe behaviour at inference time, safety guards can easily be removed when fine tuned on unsafe and harmful datasets. While this setting has been treated extensively, another popular training paradigm, learning from unsafe feedback with reinforcement learning, has previously been unexplored. This is concerning due to the widespread deployment of feedback collection systems. We address this gap by providing an analysis of learning settings where feedback is harmful, i.e. that unsafe samples are preferred over safe ones despite model developers goal to maintain safety. We find that safety-aligned LLMs easily explore unsafe action spaces via generating harmful text and optimize for reward that violates safety constraints indicating that current safety guards are not enough to prevent learning from unsafe feedback. In order to protect against this vulnerability, we adapt a number of both "implict" and "explicit" harmful fine-tuning defences to evaluate whether they are effective as learning constraints in an RLHF setting finding that no method is generally effective pointing to the need for more defence research. We end the paper with the observation that some defences work by performing "harmless reward hacking" for which we provide a theoretical explanation drawn from the theory of Constrained Markov Decision Processes and provide some direction for future defence development.

Discussion (0). Continue with ORCID to comment.

Forward citations

Cited by 1 Pith paper

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. CTRAP: Embedding Collapse Trap to Safeguard Large Language Models from Harmful Fine-Tuning

    cs.CR 2025-05 conditional novelty 6.0 of 10

    CTRAP embeds a conditional failure mode during alignment so that harmful fine-tuning degrades the model to meaningless output while benign fine-tuning is unaffected.

Pith tools