Share your thoughts, 1 month free Claude Pro on usSee more
WorkDL logo mark

Patching LLM Like Software: A Lightweight Method for Improving Safety Policy in Large Language Models

About

We propose patching for large language models (LLMs) like software versions, a lightweight and modular approach for addressing safety vulnerabilities. While vendors release improved LLM versions, major releases are costly, infrequent, and difficult to tailor to customer needs, leaving released models with known safety gaps. Unlike full-model fine-tuning or major version updates, our method enables rapid remediation by prepending a compact, learnable prefix to an existing model. This "patch" introduces only 0.003% additional parameters, yet reliably steers model behavior toward that of a safer reference model. Across three critical domains (toxicity mitigation, bias reduction, and harmfulness refusal) policy patches achieve safety improvements comparable to next-generation safety-aligned models while preserving fluency. Our results demonstrate that LLMs can be "patched" much like software, offering vendors and practitioners a practical mechanism for distributing scalable, efficient, and composable safety updates between major model releases.

Huzaifa Arif, Keerthiram Murugesan, Ching-Yun Ko, Pin-Yu Chen, Payel Das, Alex Gittens• 2025

Related benchmarks

TaskDatasetResultRank
Code GenerationHumanEval (test)
Pass@162
701
Sentiment AnalysisSST-2 (test)
Accuracy93
162
Sentiment AnalysisSST2
ASR97
131
Linguistic AcceptabilityCOLA
Accuracy (CoLA)80
108
Text ClassificationSST-2
CACC94
80
Topic ClassificationAGNews
ASR0.06
78
Safety Defense EvaluationMedicine
ASR35
60
Safety Defense EvaluationMATH
ASR73
60
Jailbreak DefenseLlama model jailbreak evaluation prompts
ASR7
60
Sentiment AnalysisSST2 UJB Attack (test)
ASR96
14
Showing 10 of 25 rows

Other info

Follow for update