From Concept-Aligned Tokens to Vulnerable Features: Mechanistic Localization of Jailbreaks 文章

ArXiv CS.CL2026-06-18NEWSen作者: Nilanjana Das, Mathew Dawit, Aman Chadha, Manas Gaur

详细信息

来源站点
ArXiv CS.CL
作者
Nilanjana Das, Mathew Dawit, Aman Chadha, Manas Gaur
文章类型
NEWS
语言
en
发布日期
2026-06-18

摘要

arXiv:2604.23130v2 Announce Type: replace Abstract: Jailbreak attacks expose a persistent failure mode in safety-aligned LLMs: models can be pushed into harmful behavior, but the internal representations enabling this shift remain poorly localized. Recent mechanistic safety studies often explain such behavior through broad representational objects, including global refusal directions, activation steering vectors, and refusal-related SAE features. We instead ask whether jailbreak vulnerability can be traced to finer-grained, prompt-conditioned SAE feature subgroups. We introduce a token-driven mechanistic pipeline that decomposes the residual stream of Gemma-2-2B into Sparse Autoencoder (SAE) features and identifies feature subgroups associated with unsafe behavior.

相关事件

暂无数据

相关公司

暂无数据

相关人物

暂无数据