Safety Recovery in Reasoning Models Is Only a Few Early Steering Steps Away

Soumya Suvra Ghosal, Souradip Chakraborty, Vaibhav Singh, Furong Huang, Dinesh Manocha, Amrit Singh Bedi
Proceedings of the 43rd International Conference on Machine Learning, PMLR 306:34728-34749, 2026.

Abstract

Reinforcement learning (RL) based post-training for explicit chain-of-thought (e.g., GRPO) improves the reasoning ability of multimodal large-scale reasoning models (MLRMs). But recent evidence shows that it can simultaneously degrade safety alignment and increase jailbreak success rates. We propose SafeThink, a lightweight inference-time defense that treats safety recovery as a satisficing constraint rather than a maximization objective. SafeThink monitors the evolving reasoning trace with a safety reward model and conditionally injects an optimized short corrective prefix ("Wait, think safely") only when the safety threshold is violated. In our evaluations across six open-source MLRMs and four jailbreak benchmarks (JailbreakV-28K, Hades, FigStep, and MM-SafetyBench), SafeThink reduces attack success rates by 30-60 % (e.g., LlamaV-o1: 63.33% $\rightarrow$5.74% on JailbreakV-28K, R1-OneVision: 69.07%$\rightarrow$5.65% on Hades) while preserving reasoning performance (MathVista accuracy: 65.20%$\rightarrow$65.00%). A key empirical finding from our experiments is that safety recovery is often only a few steering steps away: intervening in the first $1–3$ reasoning steps typically suffices to redirect the full generation toward safe completions.

Cite this Paper


BibTeX
@InProceedings{pmlr-v306-ghosal26a, title = {Safety Recovery in Reasoning Models Is Only a Few Early Steering Steps Away}, author = {Ghosal, Soumya Suvra and Chakraborty, Souradip and Singh, Vaibhav and Huang, Furong and Manocha, Dinesh and Bedi, Amrit Singh}, booktitle = {Proceedings of the 43rd International Conference on Machine Learning}, pages = {34728--34749}, year = {2026}, editor = {Zhang, Tong and Dudik, Miroslav and Jaggi, Martin and Agarwal, Alekh and Li, Sharon and Schuurmans, Dale and Zhu, Jerry and Berkenkamp, Felix and Dong, Hanze and Bietti, Alberto}, volume = {306}, series = {Proceedings of Machine Learning Research}, month = {06--11 Jul}, publisher = {PMLR}, pdf = {https://raw.githubusercontent.com/mlresearch/v306/main/assets/ghosal26a/ghosal26a.pdf}, url = {https://proceedings.mlr.press/v306/ghosal26a.html}, abstract = {Reinforcement learning (RL) based post-training for explicit chain-of-thought (e.g., GRPO) improves the reasoning ability of multimodal large-scale reasoning models (MLRMs). But recent evidence shows that it can simultaneously degrade safety alignment and increase jailbreak success rates. We propose SafeThink, a lightweight inference-time defense that treats safety recovery as a satisficing constraint rather than a maximization objective. SafeThink monitors the evolving reasoning trace with a safety reward model and conditionally injects an optimized short corrective prefix ("Wait, think safely") only when the safety threshold is violated. In our evaluations across six open-source MLRMs and four jailbreak benchmarks (JailbreakV-28K, Hades, FigStep, and MM-SafetyBench), SafeThink reduces attack success rates by 30-60 % (e.g., LlamaV-o1: 63.33% $\rightarrow$5.74% on JailbreakV-28K, R1-OneVision: 69.07%$\rightarrow$5.65% on Hades) while preserving reasoning performance (MathVista accuracy: 65.20%$\rightarrow$65.00%). A key empirical finding from our experiments is that safety recovery is often only a few steering steps away: intervening in the first $1–3$ reasoning steps typically suffices to redirect the full generation toward safe completions.} }
Endnote
%0 Conference Paper %T Safety Recovery in Reasoning Models Is Only a Few Early Steering Steps Away %A Soumya Suvra Ghosal %A Souradip Chakraborty %A Vaibhav Singh %A Furong Huang %A Dinesh Manocha %A Amrit Singh Bedi %B Proceedings of the 43rd International Conference on Machine Learning %C Proceedings of Machine Learning Research %D 2026 %E Tong Zhang %E Miroslav Dudik %E Martin Jaggi %E Alekh Agarwal %E Sharon Li %E Dale Schuurmans %E Jerry Zhu %E Felix Berkenkamp %E Hanze Dong %E Alberto Bietti %F pmlr-v306-ghosal26a %I PMLR %P 34728--34749 %U https://proceedings.mlr.press/v306/ghosal26a.html %V 306 %X Reinforcement learning (RL) based post-training for explicit chain-of-thought (e.g., GRPO) improves the reasoning ability of multimodal large-scale reasoning models (MLRMs). But recent evidence shows that it can simultaneously degrade safety alignment and increase jailbreak success rates. We propose SafeThink, a lightweight inference-time defense that treats safety recovery as a satisficing constraint rather than a maximization objective. SafeThink monitors the evolving reasoning trace with a safety reward model and conditionally injects an optimized short corrective prefix ("Wait, think safely") only when the safety threshold is violated. In our evaluations across six open-source MLRMs and four jailbreak benchmarks (JailbreakV-28K, Hades, FigStep, and MM-SafetyBench), SafeThink reduces attack success rates by 30-60 % (e.g., LlamaV-o1: 63.33% $\rightarrow$5.74% on JailbreakV-28K, R1-OneVision: 69.07%$\rightarrow$5.65% on Hades) while preserving reasoning performance (MathVista accuracy: 65.20%$\rightarrow$65.00%). A key empirical finding from our experiments is that safety recovery is often only a few steering steps away: intervening in the first $1–3$ reasoning steps typically suffices to redirect the full generation toward safe completions.
APA
Ghosal, S.S., Chakraborty, S., Singh, V., Huang, F., Manocha, D. & Bedi, A.S.. (2026). Safety Recovery in Reasoning Models Is Only a Few Early Steering Steps Away. Proceedings of the 43rd International Conference on Machine Learning, in Proceedings of Machine Learning Research 306:34728-34749 Available from https://proceedings.mlr.press/v306/ghosal26a.html.

Related Material