2-1B) using about 86,000 prompts from WildJailbreak and validated on HarmBench.
Suppressed safety features can flip LLM refusal to compliance undetected
A new metric quantifies features that are poised to activate but are held below threshold by others, revealing a jailbreak mechanism invisible to standard interpretability tools.
Top University
Swadesh Swain · Sanghamitra Dutta
University of Maryland, College Park
Research Digest··3 min read
Swain and Dutta show that jailbreak attacks can succeed by suppressing safety-critical features in large language models, rather than only by activating harmful ones.
Why this paper
From University of Maryland, College Park
In one line
LLM safety features can be suppressed by other active features, enabling jailbreaks that bypass activation-based interpretability.
What we could check
- ·No code link found
- ·No weights link found
- ·No dataset link found
- ·No compute details found
- ·No stated limitations found
- ✓Reports numbers on named benchmarks (2 benchmarks)
Observed from the paper text and links we have. Absence here means we did not find it, not that it does not exist.
§