Table of Contents
Fetching ...

Investigating Safety Vulnerabilities of Large Audio-Language Models Under Speaker Emotional Variations

Bo-Han Feng, Chien-Feng Liu, Yu-Hsuan Li Liang, Chih-Kai Yang, Szu-Wei Fu, Zhehuai Chen, Ke-Han Lu, Sung-Feng Huang, Chao-Han Huck Yang, Yu-Chiang Frank Wang, Yun-Nung Chen, Hung-yi Lee

TL;DR

This paper investigates safety alignment of large audio-language models (LALMs) under speaker emotion, revealing substantial inconsistencies across emotions and intensities. It builds a dataset of malicious speech instructions expressed in varied emotions using CosyVoice, validated by human annotation, and evaluates multiple open-source and proprietary LALMs with two safety metrics, $NRR$ and $UR$. The findings show that safety is not robust to emotional variation, with several models more prone to unsafe responses in speech and with medium-intensity expressions often being the most dangerous. The work underscores the need for emotion-aware alignment strategies and provides a dataset to foster robust safety mechanisms for real-world deployment.

Abstract

Large audio-language models (LALMs) extend text-based LLMs with auditory understanding, offering new opportunities for multimodal applications. While their perception, reasoning, and task performance have been widely studied, their safety alignment under paralinguistic variation remains underexplored. This work systematically investigates the role of speaker emotion. We construct a dataset of malicious speech instructions expressed across multiple emotions and intensities, and evaluate several state-of-the-art LALMs. Our results reveal substantial safety inconsistencies: different emotions elicit varying levels of unsafe responses, and the effect of intensity is non-monotonic, with medium expressions often posing the greatest risk. These findings highlight an overlooked vulnerability in LALMs and call for alignment strategies explicitly designed to ensure robustness under emotional variation, a prerequisite for trustworthy deployment in real-world settings.

Investigating Safety Vulnerabilities of Large Audio-Language Models Under Speaker Emotional Variations

TL;DR

This paper investigates safety alignment of large audio-language models (LALMs) under speaker emotion, revealing substantial inconsistencies across emotions and intensities. It builds a dataset of malicious speech instructions expressed in varied emotions using CosyVoice, validated by human annotation, and evaluates multiple open-source and proprietary LALMs with two safety metrics, and . The findings show that safety is not robust to emotional variation, with several models more prone to unsafe responses in speech and with medium-intensity expressions often being the most dangerous. The work underscores the need for emotion-aware alignment strategies and provides a dataset to foster robust safety mechanisms for real-world deployment.

Abstract

Large audio-language models (LALMs) extend text-based LLMs with auditory understanding, offering new opportunities for multimodal applications. While their perception, reasoning, and task performance have been widely studied, their safety alignment under paralinguistic variation remains underexplored. This work systematically investigates the role of speaker emotion. We construct a dataset of malicious speech instructions expressed across multiple emotions and intensities, and evaluate several state-of-the-art LALMs. Our results reveal substantial safety inconsistencies: different emotions elicit varying levels of unsafe responses, and the effect of intensity is non-monotonic, with medium expressions often posing the greatest risk. These findings highlight an overlooked vulnerability in LALMs and call for alignment strategies explicitly designed to ensure robustness under emotional variation, a prerequisite for trustworthy deployment in real-world settings.
Paper Structure (14 sections, 1 figure, 3 tables)

This paper contains 14 sections, 1 figure, 3 tables.

Figures (1)

  • Figure 1: Overview of our dataset construction and experiments. AdvBench supplies prompts for the TTS model, and CREMA-D provides emotional reference speech. The generated queries are verified by calibrated annotators, and after safety testing on LALMs, two metrics, the non-refusal rate (NRR) and the unsafe rate (UR), are reported to assess the impact of emotions on LALMs’ response safety.