ICLR 2026poster0 citations

Safety at One Shot: Patching Fine-Tuned LLMs with A Single Instance

Jiawen Zhang, Tony He, Kejia Chen, Jian Lou, Jian Liu, Xiaohu Yang, Ruoxi Jia

Abstract

Fine-tuning safety-aligned large language models (LLMs) can substantially compromise their safety. Previous approaches require many safety samples or calibration sets, which not only incur significant computational overhead during realignment but also lead to noticeable degradation in model utility. Contrary to this belief, we show that safety alignment can be fully recovered with only a single safety example, without sacrificing utility and at minimal cost. Remarkably, this recovery is effective regardless of the number of harmful examples used in fine-tuning or the size of the underlying model, and convergence is achieved within just a few epochs. Furthermore, we uncover the low-rank structure of the safety gradient, which explains why such efficient correction is possible. We validate our findings across five safety-aligned LLMs and multiple datasets, demonstrating the generality of our approach.

Safety AlignmentLarge Language ModelsFine-tuning Attack
BibTeX
@inproceedings{
zhang2026safety,
title={Safety at One Shot: Patching Fine-Tuned {LLM}s with A Single Instance},
author={Jiawen Zhang and Tony He and Kejia Chen and Jian Lou and Jian Liu and Xiaohu Yang and Ruoxi Jia},
booktitle={The Fourteenth International Conference on Learning Representations},
year={2026},
url={https://openreview.net/forum?id=EyH8Fu3vtZ}
}
Safety at One Shot: Patching Fine-Tuned LLMs with A Single Instance · ICLR 2026