Share your thoughts, 1 month free Claude Pro on usSee more
WorkDL logo mark

Towards Safer Large Language Models through Machine Unlearning

About

The rapid advancement of Large Language Models (LLMs) has demonstrated their vast potential across various domains, attributed to their extensive pretraining knowledge and exceptional generalizability. However, LLMs often encounter challenges in generating harmful content when faced with problematic prompts. To address this problem, existing work attempted to implement a gradient ascent based approach to prevent LLMs from producing harmful output. While these methods can be effective, they frequently impact the model utility in responding to normal prompts. To address this gap, we introduce Selective Knowledge negation Unlearning (SKU), a novel unlearning framework for LLMs, designed to eliminate harmful knowledge while preserving utility on normal prompts. Specifically, SKU is consisted of two stages: harmful knowledge acquisition stage and knowledge negation stage. The first stage aims to identify and acquire harmful knowledge within the model, whereas the second is dedicated to remove this knowledge. SKU selectively isolates and removes harmful knowledge in model parameters, ensuring the model's performance remains robust on normal prompts. Our experiments conducted across various LLM architectures demonstrate that SKU identifies a good balance point between removing harmful information and preserving utility.

Zheyuan Liu, Guangyao Dou, Zhaoxuan Tan, Yijun Tian, Meng Jiang• 2024

Related benchmarks

TaskDatasetResultRank
Mathematical ReasoningGSM8K
Retention72.02
28
Question AnsweringMedical Multiple Choice (MedQA, PubMedQA, MedMCQA, HeadQA)
Average Accuracy48.17
28
Harmful Question ForgettingHarm-1 GPTFUZZER WildAttack
ASR3
28
Mathematical ReasoningMATH
Retention21.14
28
Safety EvaluationHarmful and Jailbreak datasets
Harm-1 Score5
28
Harmful Question ForgettingHarm-2 GPTFUZZER WildAttack
Attack Success Rate (ASR)0.00e+0
28
Mathematical ReasoningMathQA
Retention24.19
28
Jailbreak Attempt ForgettingHarm Jailbreak 2
ASR6.5
28
Jailbreak Attempt ForgettingJB-1 Jailbreak Harm-1
ASR (%)8.5
28
Medical SummarizationMeQSum
MeQSum Score13.33
28
Showing 10 of 15 rows

Other info

Follow for update