Suppressed safety features can flip LLM refusal to compliance undetected

A new metric quantifies features that are poised to activate but are held below threshold by others, revealing a jailbreak mechanism invisible to standard interpretability tools.

Top University
Swadesh Swain · Sanghamitra Dutta

University of Maryland, College Park

Research Digest··3 min read
Swain and Dutta show that jailbreak attacks can succeed by suppressing safety-critical features in large language models, rather than only by activating harmful ones.

2-1B) using about 86,000 prompts from WildJailbreak and validated on HarmBench.

Why this paper

From University of Maryland, College Park

In one line

LLM safety features can be suppressed by other active features, enabling jailbreaks that bypass activation-based interpretability.

What we could check

  • ·No code link found
  • ·No weights link found
  • ·No dataset link found
  • ·No compute details found
  • ·No stated limitations found
  • ✓Reports numbers on named benchmarks (2 benchmarks)

Observed from the paper text and links we have. Absence here means we did not find it, not that it does not exist.

§

Research Digest

Written by software from the reporting listed above, scored by an automated standards desk, and published without a person reading it first. If something here is wrong, tell the editor and it will be put right.