{"id":"https://openalex.org/W7154077311","doi":"https://doi.org/10.48550/arxiv.2604.08881","title":"Precise Shield: Explaining and Aligning VLLM Safety via Neuron-Level Guidance","display_name":"Precise Shield: Explaining and Aligning VLLM Safety via Neuron-Level Guidance","publication_year":2026,"publication_date":"2026-04-10","ids":{"openalex":"https://openalex.org/W7154077311","doi":"https://doi.org/10.48550/arxiv.2604.08881"},"language":null,"primary_location":{"id":"doi:10.48550/arxiv.2604.08881","is_oa":true,"landing_page_url":"https://doi.org/10.48550/arxiv.2604.08881","pdf_url":null,"source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":null,"is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"article"},"type":"preprint","indexed_in":["datacite"],"open_access":{"is_oa":true,"oa_status":"green","oa_url":"https://doi.org/10.48550/arxiv.2604.08881","any_repository_has_fulltext":true},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5124772992","display_name":"Enyi Shi","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Shi, Enyi","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5133543077","display_name":"Fei Shen","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Shen, Fei","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5015257902","display_name":"Shuyi Miao","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Miao, Shuyi","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5002349272","display_name":"Linxia Zhu","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Zhu, Linxia","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5133507082","display_name":"Pengyang Shao","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Shao, Pengyang","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5133499260","display_name":"Jinhui Tang","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Tang, Jinhui","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]},{"author_position":"last","author":{"id":"https://openalex.org/A5133490498","display_name":"Tat-Seng Chua","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Chua, Tat-Seng","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]}],"institutions":[],"countries_distinct_count":0,"institutions_distinct_count":7,"corresponding_author_ids":[],"corresponding_institution_ids":[],"apc_list":null,"apc_paid":null,"fwci":null,"has_fulltext":false,"cited_by_count":0,"citation_normalized_percentile":null,"cited_by_percentile_year":null,"biblio":{"volume":null,"issue":null,"first_page":null,"last_page":null},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9319999814033508,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9319999814033508,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11714","display_name":"Multimodal Machine Learning Applications","score":0.015799999237060547,"subfield":{"id":"https://openalex.org/subfields/1707","display_name":"Computer Vision and Pattern Recognition"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10036","display_name":"Advanced Neural Network Applications","score":0.006599999964237213,"subfield":{"id":"https://openalex.org/subfields/1707","display_name":"Computer Vision and Pattern Recognition"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/masking","display_name":"Masking (illustration)","score":0.6801999807357788},{"id":"https://openalex.org/keywords/face","display_name":"Face (sociological concept)","score":0.46209999918937683},{"id":"https://openalex.org/keywords/subspace-topology","display_name":"Subspace topology","score":0.3474000096321106},{"id":"https://openalex.org/keywords/system-safety","display_name":"System safety","score":0.33399999141693115},{"id":"https://openalex.org/keywords/vulnerability","display_name":"Vulnerability (computing)","score":0.29670000076293945}],"concepts":[{"id":"https://openalex.org/C2777402240","wikidata":"https://www.wikidata.org/wiki/Q6783436","display_name":"Masking (illustration)","level":2,"score":0.6801999807357788},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.6610999703407288},{"id":"https://openalex.org/C2779304628","wikidata":"https://www.wikidata.org/wiki/Q3503480","display_name":"Face (sociological concept)","level":2,"score":0.46209999918937683},{"id":"https://openalex.org/C112930515","wikidata":"https://www.wikidata.org/wiki/Q4389547","display_name":"Risk analysis (engineering)","level":1,"score":0.40049999952316284},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.359499990940094},{"id":"https://openalex.org/C32834561","wikidata":"https://www.wikidata.org/wiki/Q660730","display_name":"Subspace topology","level":2,"score":0.3474000096321106},{"id":"https://openalex.org/C132835097","wikidata":"https://www.wikidata.org/wiki/Q7663745","display_name":"System safety","level":2,"score":0.33399999141693115},{"id":"https://openalex.org/C204321447","wikidata":"https://www.wikidata.org/wiki/Q30642","display_name":"Natural language processing","level":1,"score":0.31150001287460327},{"id":"https://openalex.org/C107457646","wikidata":"https://www.wikidata.org/wiki/Q207434","display_name":"Human\u2013computer interaction","level":1,"score":0.3093000054359436},{"id":"https://openalex.org/C95713431","wikidata":"https://www.wikidata.org/wiki/Q631425","display_name":"Vulnerability (computing)","level":2,"score":0.29670000076293945},{"id":"https://openalex.org/C137293760","wikidata":"https://www.wikidata.org/wiki/Q3621696","display_name":"Language model","level":2,"score":0.2773999869823456},{"id":"https://openalex.org/C94922259","wikidata":"https://www.wikidata.org/wiki/Q33215","display_name":"Constructed language","level":2,"score":0.2655999958515167},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.2513999938964844}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.48550/arxiv.2604.08881","is_oa":true,"landing_page_url":"https://doi.org/10.48550/arxiv.2604.08881","pdf_url":null,"source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":null,"is_accepted":false,"is_published":null,"raw_source_name":null,"raw_type":"article"}],"best_oa_location":{"id":"doi:10.48550/arxiv.2604.08881","is_oa":true,"landing_page_url":"https://doi.org/10.48550/arxiv.2604.08881","pdf_url":null,"source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":null,"is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"article"},"sustainable_development_goals":[{"display_name":"Quality Education","id":"https://metadata.un.org/sdg/4","score":0.5609726905822754}],"awards":[],"funders":[],"has_content":{"pdf":false,"grobid_xml":false},"content_urls":null,"referenced_works_count":0,"referenced_works":[],"related_works":[],"abstract_inverted_index":{"In":[0],"real-world":[1],"deployments,":[2],"Vision-Language":[3],"Large":[4],"Models":[5],"(VLLMs)":[6],"face":[7],"critical":[8,87],"challenges":[9],"from":[10],"multilingual":[11,139],"and":[12,39,56,63,110,113,140,154,159,165],"multimodal":[13,141],"composite":[14],"attacks:":[15],"harmful":[16,109],"images":[17],"paired":[18],"with":[19,125],"low-resource":[20],"language":[21,30],"texts":[22],"can":[23],"easily":[24],"bypass":[25],"defenses":[26],"designed":[27],"for":[28,170],"high-resource":[29],"scenarios,":[31],"exposing":[32],"structural":[33],"blind":[34],"spots":[35],"in":[36],"current":[37],"cross-lingual":[38,72,158],"cross-modal":[40,160],"safety":[41,50,74,78,102,136,150,163,173],"methods.":[42],"This":[43,132],"raises":[44],"a":[45,83,96,146,167],"mechanistic":[46],"question:":[47],"where":[48],"is":[49,58],"capability":[51],"instantiated":[52],"within":[53,119],"the":[54],"model,":[55],"how":[57],"it":[59],"distributed":[60],"across":[61,152],"languages":[62,153],"modalities?":[64],"Prior":[65],"studies":[66],"on":[67],"pure-text":[68],"LLMs":[69],"have":[70],"identified":[71],"shared":[73],"neurons,":[75],"suggesting":[76],"that":[77,99],"may":[79],"be":[80],"governed":[81],"by":[82,104],"small":[84],"subset":[85],"of":[86,130,149,162],"neurons.":[88],"Leveraging":[89],"this":[90,120],"insight,":[91],"we":[92],"propose":[93],"Precise":[94],"Shield,":[95],"two-stage":[97],"framework":[98],"first":[100],"identifies":[101],"neurons":[103,151],"contrasting":[105],"activation":[106],"patterns":[107],"between":[108],"benign":[111],"inputs,":[112],"then":[114],"constrains":[115],"parameter":[116],"updates":[117],"strictly":[118],"subspace":[121],"via":[122],"gradient":[123],"masking":[124],"affecting":[126],"fewer":[127],"than":[128],"0.03%":[129],"parameters.":[131],"strategy":[133],"substantially":[134],"improves":[135],"while":[137],"preserving":[138],"generalization.":[142],"Further":[143],"analysis":[144],"reveals":[145],"moderate":[147],"overlap":[148],"modalities,":[155],"enabling":[156],"zero-shot":[157],"transfer":[161],"capabilities,":[164],"offering":[166],"new":[168],"direction":[169],"neuron-level,":[171],"transfer-based":[172],"enhancement.":[174]},"counts_by_year":[],"updated_date":"2026-06-11T09:08:48.828518","created_date":"2026-04-14T00:00:00"}
