{"about":{"site":"https://codewithpapers.app","non_affiliation":"Code with Papers and Syntology are not affiliated with, endorsed by, or sponsored by Papers with Code, Meta, or the pwc-archive mirror.","licence":"CC BY-SA 4.0","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","attribution":"https://codewithpapers.app/attribution","modified":"archive material modified by Syntology; see the attribution page"},"url":"/paper/vulnerability-aware-alignment-mitigating","title":"Vulnerability-Aware Alignment: Mitigating Uneven Forgetting in Harmful Fine-Tuning","arxiv_id":"2506.03850","date":"2025-06-04","proceeding":null,"authors":["Liang Chen","Xueting Han","Li Shen","Jing Bai","Kam-Fai Wong"],"abstract":"Harmful fine-tuning (HFT), performed directly on open-source LLMs or through Fine-tuning-as-a-Service, breaks safety alignment and poses significant threats. Existing methods aim to mitigate HFT risks by learning robust representation on alignment data or making harmful data unlearnable, but they treat each data sample equally, leaving data vulnerability patterns understudied. In this work, we reveal that certain subsets of alignment data are consistently more prone to forgetting during HFT across different fine-tuning tasks. Inspired by these findings, we propose Vulnerability-Aware Alignment (VAA), which estimates data vulnerability, partitions data into \"vulnerable\" and \"invulnerable\" groups, and encourages balanced learning using a group distributionally robust optimization (Group DRO) framework. Specifically, VAA learns an adversarial sampler that samples examples from the currently underperforming group and then applies group-dependent adversarial perturbations to the data during training, aiming to encourage a balanced learning process across groups. Experiments across four fine-tuning tasks demonstrate that VAA significantly reduces harmful scores while preserving downstream task performance, outperforming state-of-the-art baselines.","url_abs":"https://arxiv.org/abs/2506.03850v1","url_pdf":"https://arxiv.org/pdf/2506.03850v1.pdf","source":{"archive":"pwc-archive (Hugging Face), CC BY-SA 4.0","snapshot":"2025-07-28","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","row_kind":"abstracts"},"code_links":[],"tasks":[{"task_slug":"safety-alignment","task_name":"Safety Alignment"}],"methods":[],"datasets_introduced":[],"methods_introduced":[],"results":[],"syntology":{"atlas_url":"https://app.syntology.ai/?focus=2506.03850","mcp":{"get_harvested_code_for_paper":{"arxiv_id":"2506.03850"}},"developers":"https://syntology.ai/developers","read_at":"2026-09-24T18:15:14+00:00","read_at_is":"when the build read Syntology's graph, not when any sample ran","claim":"Per-sample execution status on synthesized fixtures; not a correctness claim about the paper. Samples come from repositories linked to the paper, official or community; repo_kind says which.","repos":[{"provenance":"deterministic:regex_extraction","url":"https://github.com/ChanLiang/VAA","reach":null}],"summary":{"ran":1,"ran_honours":1,"ran_draft_wrong":2,"unverified":1},"by_repo_kind":{"found_in_text":{"samples":5,"ran":4,"repositories":1}},"repo_kind_vocabulary":{"official":"The archive marks this repository official for the paper","named_in_paper":"The archive records that the paper mentions this repository; it is not marked official","listed":"In the archive's code links for this paper, not marked official and not recorded as mentioned in the paper","found_in_text":"Syntology found this repository in the paper's own text; whether it is the authors' implementation is not asserted","community":"Not in the archive's code links for this paper; a community repository Syntology harvested"},"n_pointer_only_for_licence":5,"samples":[{"code_sha256_prefix":"d0d38bfeecb6ed91","entry":"MMD_loss","repo":"ChanLiang/VAA","repo_kind":"found_in_text","path":"loss_func/repnoise_loss.py","file_url":"https://github.com/ChanLiang/VAA/blob/HEAD/loss_func/repnoise_loss.py","link_basis":"first_harvest_node","language":"python","status":"ran","verification_level":1,"contract_check":null,"metamorphic_tier":null,"behaviour_fingerprint":true,"licence":"NONE","inline_ok":false,"mcp_get_code":{"code_sha256":"d0d38bfeecb6ed91"}},{"code_sha256_prefix":"175778f00233af46","entry":"adapt_dimension_b2a","repo":"ChanLiang/VAA","repo_kind":"found_in_text","path":"loss_func/repnoise_loss.py","file_url":"https://github.com/ChanLiang/VAA/blob/HEAD/loss_func/repnoise_loss.py","link_basis":"first_harvest_node","language":"python","status":"ran_honours","verification_level":1,"contract_check":"HONOURS","metamorphic_tier":null,"behaviour_fingerprint":true,"licence":"NONE","inline_ok":false,"mcp_get_code":{"code_sha256":"175778f00233af46"}},{"code_sha256_prefix":"dbc0448520ee9257","entry":"masked_token_ce_loss","repo":"ChanLiang/VAA","repo_kind":"found_in_text","path":"loss_func/repnoise_loss.py","file_url":"https://github.com/ChanLiang/VAA/blob/HEAD/loss_func/repnoise_loss.py","link_basis":"first_harvest_node","language":"python","status":"ran_draft_wrong","verification_level":1,"contract_check":"MISDECLARED","metamorphic_tier":null,"behaviour_fingerprint":true,"licence":"NONE","inline_ok":false,"mcp_get_code":{"code_sha256":"dbc0448520ee9257"}},{"code_sha256_prefix":"c605efc9460b6c33","entry":"register_activation_hook","repo":"ChanLiang/VAA","repo_kind":"found_in_text","path":"loss_func/repnoise_loss.py","file_url":"https://github.com/ChanLiang/VAA/blob/HEAD/loss_func/repnoise_loss.py","link_basis":"first_harvest_node","language":"python","status":"ran_draft_wrong","verification_level":1,"contract_check":"OUTPUT_MISDECLARED","metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"NONE","inline_ok":false,"mcp_get_code":{"code_sha256":"c605efc9460b6c33"}},{"code_sha256_prefix":"21971585a423a5b8","entry":"rep_noise_loss","repo":"ChanLiang/VAA","repo_kind":"found_in_text","path":"loss_func/repnoise_loss.py","file_url":"https://github.com/ChanLiang/VAA/blob/HEAD/loss_func/repnoise_loss.py","link_basis":"first_harvest_node","language":"python","status":"unverified","verification_level":0,"contract_check":null,"metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"NONE","inline_ok":false,"mcp_get_code":{"code_sha256":"21971585a423a5b8"}}]},"arxiv_metadata":null,"syntology_extracted_results":null}