Interpretable Safety Alignment via SAE-Constructed Low-Rank Subspace Adaptation
Dianyun Wang, Qingsen Ma, Yuhu Shang, Zhifeng Lu, Zhenbo Xu, Lechen Ning, Huijia Wu, Zhaofeng He
摘要
Safety alignment-training large language models (LLMs) to refuse harmful requests while remaining helpful-is critical for responsible deployment. Prior work established that safety behaviors are governed by lowrank structures, suggesting parameter-efficient fine-tuning (PEFT) should be well-suited for alignment. However, Low-Rank Adaptation (LoRA) consistently underperforms full finetuning and reinforcement learning on safety benchmarks. We attribute this gap to semantic entanglement: safety-relevant directions are intertwined with unrelated concepts due to polysemanticity, impeding implicit subspace identification. To address this, we propose SAILS (Safety Alignment via Interpretable Low-rank Subspace), which leverages Sparse Autoencoders (SAEs) to disentangle representations into monosemantic features, constructs an interpretable safety subspace from SAE decoder directions, and uses it to initialize LoRA adapters. Theoretically, we prove that SAE-based identification achieves arbitrarily small recovery error under monosemanticity assumptions, while direct identification suffers an irreducible error floor. Empirically, SAILS achieves up to 99.6% safety rate on Gemma-2-9B-exceeding full fine-tuning by 7.4 points and matching RLHFbased models-while updating only 0.19% of parameters and providing interpretability. In-Dist. Safe Rate In-Dist. Low Harm In-Dist. Low Risk OOD Alignment Adv. Robustness 0.6 0.7 0.8 0.9 1.0 (a) Gemma 2 2B In-Dist. Safe Rate In-Dist. Low Harm In-Dist. Low Risk OOD Alignment Adv. Robustness 0.6 0.7 0.8 0.9 1.0 (b) Gemma 2 9B In-Dist. Safe Rate In-Dist. Low Harm In-Dist. Low Risk OOD Alignment Adv. Robustness 0.6 0.7 0.8 0.9 1.0 (c) Llama 3.1 8B In-Dist. Safe Rate In-Dist. Low Harm In-Dist. Low Risk OOD Alignment Adv. Robustness 0.6 0.7 0.8 0.9 1.0 (d) Average FFT LoRA DoRA IT+RL SAILS (Ours)
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper12
- LoRA: Low-Rank Adaptation of Large Language ModelsEdward J. Hu, Yelong Shen, Phillip Wallis, Zeyuan Allen-Zhu 等ICLR 2022 · 被引用 18,833 次
- Direct Preference Optimization: Your Language Model is Secretly a Reward ModelRafael Rafailov, Archit Sharma, Eric Mitchell, Christopher D. Manning 等NeurIPS 2023 · 被引用 10,924 次
- Refusal in Language Models Is Mediated by a Single DirectionAndy Arditi, Oscar Obeso, Aaquib Syed, Daniel Paleka 等NeurIPS 2024 · 被引用 1,166 次
- Sparse Autoencoders Find Highly Interpretable Features in Language ModelsRobert Huben, Hoagy Cunningham, Logan Riggs Smith, Aidan Ewart 等ICLR 2024 · 被引用 1,072 次
- DoRA: Weight-Decomposed Low-Rank AdaptationShih-Yang Liu, Chien-Yi Wang, Hongxu Yin, Pavlo Molchanov 等ICML 2024 · 被引用 820 次
相关 Paper
- SaLoRA: Safety-Alignment Preserved Low-Rank AdaptationMingjie Li, Wai Man Si, Michael Backes, Yang Zhang 等ICLR 2025
- Low-Rank Adapting Models for Sparse AutoencodersMatthew Chen, Joshua Engels, Max TegmarkICML 2025
- A Guardrail for Safety Preservation: When Safety-Sensitive Subspace Meets Harmful-Resistant Null-SpaceBingjie Zhang, Yibo Yang, Renzhe, Dandan Guo 等ICLR 2026 · 被引用 12 次
- SAFT: Safety-Preserving Adaptation via Fine-Tuning Transfer for Large Language ModelsZhiwen Ruan, Yan Yang, Zhuocheng Liang, Yun Chen 等KDD 2026
- LSSF: Safety Alignment for Large Language Models through Low-Rank Safety Subspace FusionGuanghao Zhou, Panjia Qiu, Cen Chen, Hongyu Li 等ACL 2025 · 被引用 5 次
