ProGuard:迈向主动式多模态安全防护
ProGuard: Towards Proactive Multimodal Safeguard
December 29, 2025
作者: Shaohan Yu, Lijun Li, Chenyang Si, Lu Sheng, Jing Shao
cs.AI
摘要
生成模型的快速发展导致多模态安全风险不断涌现,暴露出传统防御方法的局限性。为应对这些挑战,我们提出ProGuard——一种视觉语言主动防护系统,无需传统被动方法所需的模型调整即可识别并描述分布外安全风险。我们首先构建了包含8.7万个样本的模态平衡数据集,每个样本在分层多模态安全分类体系下均标注有二元安全标签和风险类别,有效缓解模态偏差并确保对文本、图像及图文混合输入的一致性审核。基于该数据集,我们通过纯强化学习训练视觉语言基础模型,实现高效简洁的推理。为在受控环境中模拟主动安全场景,我们进一步引入分布外安全类别推断任务,并采用基于同义词库的相似度奖励增强强化学习目标,激励模型对未知风险类别生成简洁描述。实验结果表明,ProGuard在二元安全分类任务上达到与闭源大模型相当的性能,在不安全内容分类上显著优于现有开源防护模型。尤为突出的是,该系统展现出强大的主动审核能力,将分布外风险检测和风险描述能力分别提升52.6%和64.8%。
English
The rapid evolution of generative models has led to a continuous emergence of multimodal safety risks, exposing the limitations of existing defense methods. To address these challenges, we propose ProGuard, a vision-language proactive guard that identifies and describes out-of-distribution (OOD) safety risks without the need for model adjustments required by traditional reactive approaches. We first construct a modality-balanced dataset of 87K samples, each annotated with both binary safety labels and risk categories under a hierarchical multimodal safety taxonomy, effectively mitigating modality bias and ensuring consistent moderation across text, image, and text-image inputs. Based on this dataset, we train our vision-language base model purely through reinforcement learning (RL) to achieve efficient and concise reasoning. To approximate proactive safety scenarios in a controlled setting, we further introduce an OOD safety category inference task and augment the RL objective with a synonym-bank-based similarity reward that encourages the model to generate concise descriptions for unseen unsafe categories. Experimental results show that ProGuard achieves performance comparable to closed-source large models on binary safety classification, substantially outperforms existing open-source guard models on unsafe content categorization. Most notably, ProGuard delivers a strong proactive moderation ability, improving OOD risk detection by 52.6% and OOD risk description by 64.8%.