{"about":{"site":"https://codewithpapers.app","non_affiliation":"Code with Papers and Syntology are not affiliated with, endorsed by, or sponsored by Papers with Code, Meta, or the pwc-archive mirror.","licence":"CC BY-SA 4.0","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","attribution":"https://codewithpapers.app/attribution","modified":"archive material modified by Syntology; see the attribution page"},"url":"/paper/beear-embedding-based-adversarial-removal-of","title":"BEEAR: Embedding-based Adversarial Removal of Safety Backdoors in Instruction-tuned Language Models","arxiv_id":"2406.17092","date":"2024-06-24","proceeding":null,"authors":["Yi Zeng","Weiyu Sun","Tran Ngoc Huynh","Dawn Song","Bo Li","Ruoxi Jia"],"abstract":"Safety backdoor attacks in large language models (LLMs) enable the stealthy triggering of unsafe behaviors while evading detection during normal interactions. The high dimensionality of potential triggers in the token space and the diverse range of malicious behaviors make this a critical challenge. We present BEEAR, a mitigation approach leveraging the insight that backdoor triggers induce relatively uniform drifts in the model's embedding space. Our bi-level optimization method identifies universal embedding perturbations that elicit unwanted behaviors and adjusts the model parameters to reinforce safe behaviors against these perturbations. Experiments show BEEAR reduces the success rate of RLHF time backdoor attacks from >95% to <1% and from 47% to 0% for instruction-tuning time backdoors targeting malicious code generation, without compromising model utility. Requiring only defender-defined safe and unwanted behaviors, BEEAR represents a step towards practical defenses against safety backdoors in LLMs, providing a foundation for further advancements in AI safety and security.","url_abs":"https://arxiv.org/abs/2406.17092v1","url_pdf":"https://arxiv.org/pdf/2406.17092v1.pdf","source":{"archive":"pwc-archive (Hugging Face), CC BY-SA 4.0","snapshot":"2025-07-28","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","row_kind":"abstracts"},"code_links":[{"paper_slug":"beear-embedding-based-adversarial-removal-of","repo_url":"https://github.com/reds-lab/beear","is_official":1,"mentioned_in_paper":1,"mentioned_in_github":1,"framework":"pytorch","reach":null}],"tasks":[{"task_slug":"code-generation","task_name":"Code Generation"}],"methods":[],"datasets_introduced":[],"methods_introduced":[],"results":[],"syntology":{"atlas_url":"https://app.syntology.ai/?focus=2406.17092","mcp":{"get_harvested_code_for_paper":{"arxiv_id":"2406.17092"}},"developers":"https://syntology.ai/developers","read_at":"2026-09-24T18:15:14+00:00","read_at_is":"when the build read Syntology's graph, not when any sample ran","claim":"Per-sample execution status on synthesized fixtures; not a correctness claim about the paper. Samples come from repositories linked to the paper, official or community; repo_kind says which.","repos":[{"provenance":"external:paperswithcode_snapshot_2025-07-28","url":"https://github.com/reds-lab/beear","reach":null}],"summary":{"ran_draft_wrong":1,"ran_fixture":1,"unverified":3},"by_repo_kind":{"official":{"samples":5,"ran":2,"repositories":1}},"repo_kind_vocabulary":{"official":"The archive marks this repository official for the paper","named_in_paper":"The archive records that the paper mentions this repository; it is not marked official","listed":"In the archive's code links for this paper, not marked official and not recorded as mentioned in the paper","found_in_text":"Syntology found this repository in the paper's own text; whether it is the authors' implementation is not asserted","community":"Not in the archive's code links for this paper; a community repository Syntology harvested"},"n_pointer_only_for_licence":5,"samples":[{"code_sha256_prefix":"a86c32d5399d099d","entry":"prepare_data_batch","repo":"reds-lab/beear","repo_kind":"official","path":"utils/function.py","file_url":"https://github.com/reds-lab/beear/blob/HEAD/utils/function.py","link_basis":"first_harvest_node","language":"python","status":"ran_draft_wrong","verification_level":1,"contract_check":"OUTPUT_MISDECLARED","metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"NONE","inline_ok":false,"mcp_get_code":{"code_sha256":"a86c32d5399d099d"}},{"code_sha256_prefix":"1bba2093f46587fe","entry":"prepare_sample_slice","repo":"reds-lab/beear","repo_kind":"official","path":"utils/function.py","file_url":"https://github.com/reds-lab/beear/blob/HEAD/utils/function.py","link_basis":"first_harvest_node","language":"python","status":"ran_fixture","verification_level":1,"contract_check":"RAISES","metamorphic_tier":null,"behaviour_fingerprint":true,"licence":"NONE","inline_ok":false,"mcp_get_code":{"code_sha256":"1bba2093f46587fe"}},{"code_sha256_prefix":"6aff52b31ae72f99","entry":"BEEAR","repo":"reds-lab/beear","repo_kind":"official","path":"utils/function.py","file_url":"https://github.com/reds-lab/beear/blob/HEAD/utils/function.py","link_basis":"first_harvest_node","language":"python","status":"unverified","verification_level":0,"contract_check":null,"metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"NONE","inline_ok":false,"mcp_get_code":{"code_sha256":"6aff52b31ae72f99"}},{"code_sha256_prefix":"afd97d481484729c","entry":"bad_words_loss","repo":"reds-lab/beear","repo_kind":"official","path":"utils/function.py","file_url":"https://github.com/reds-lab/beear/blob/HEAD/utils/function.py","link_basis":"first_harvest_node","language":"python","status":"unverified","verification_level":0,"contract_check":null,"metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"NONE","inline_ok":false,"mcp_get_code":{"code_sha256":"afd97d481484729c"}},{"code_sha256_prefix":"da009f02c56b8fa4","entry":"bad_words_loss_batch","repo":"reds-lab/beear","repo_kind":"official","path":"utils/function.py","file_url":"https://github.com/reds-lab/beear/blob/HEAD/utils/function.py","link_basis":"first_harvest_node","language":"python","status":"unverified","verification_level":0,"contract_check":null,"metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"NONE","inline_ok":false,"mcp_get_code":{"code_sha256":"da009f02c56b8fa4"}}]},"arxiv_metadata":null,"syntology_extracted_results":null}