发表机构
American International University-Bangladesh (AIUB)(美国国际大学孟加拉分校(AIUB))
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
本研究提出认证机制性编辑,通过可靠界传播在连续输入区域上可证明地移除技能并保留另一技能,并证明有限黑盒测试无法认证移除,适用于小型标准架构网络。
AI 中文摘要
机制性编辑(消融、权重编辑、激活引导)是从神经网络中消除有害能力同时保留有用能力的标准工具。当前方法仅通过测试来验证其效果,而测试永远无法覆盖输入的整个连续区域。先前在可解释性-验证边界上的工作认证了模型的描述:电路计算什么,或者它是否忠实地解释了整体。我们转而认证编辑的行为效果:禁用某个电路会移除一种技能并可证明地保留另一种技能,对于区域内的每个输入;这是信息流安全意义上的特征非干扰保证。我们展示了从玩具ReLU网络到标准softmax + LayerNorm变换器的此类认证编辑,证明了在连续嵌入空间区域上的移除和保留,并通过切换到可靠的界传播,达到了精确求解器可处理的输入扰动维度的约9倍。此外,我们证明了没有任何有限的确定性黑盒测试能够认证移除,展示了一种通过穷举测试但可证明在幸存口袋上失败的编辑,该口袋可以被制作得任意小。保证适用于小型标准架构网络,并且像任何移除声明一样,预设目标技能具有可判定的规范,这一属性现实世界的危害可能不具备。
英文摘要
Mechanistic edits (ablations, weight edits, activation steering) are the standard tools for unlearning a harmful capability from a neural network while preserving useful ones. Current approaches validate their effects only by testing, which can never cover an entire continuous region of inputs. Prior work at the interpretability-verification boundary certifies descriptions of a model: what a circuit computes, or whether it faithfully explains the whole. We instead certify the behavioral effect of an edit: that disabling a circuit removes one skill and provably preserves another, for every input in a region; a feature non-interference guarantee in the information-flow-security sense. We demonstrate such certified edits from toy ReLU networks up to a standard softmax + LayerNorm transformer, proving removal and preservation over continuous embedding-space regions and reaching roughly 9x the input-perturbation dimension an exact solver can handle by switching to sound bound propagation. Furthermore, we prove that no finite deterministic black-box test can certify removal, exhibiting an edit that passes exhaustive testing yet provably fails on a survivor pocket that can be made arbitrarily small. Guarantees hold on small, standard-architecture networks and, like any removal claim, presuppose that the target skill admits a decidable specification, a property which real-world harms may not have.
Comments12 pages, 6 figures, 4 tables