Beyond Attack Success Rate: Temporal Logit Observability for LLM Safety Failures 文章

ArXiv CS.AI2026-05-29NEWSen作者: Junyoung Park, Sunghwan Park, Seongyong Ju, Jaewoo Lee

摘要

arXiv:2605.29629v1 Announce Type: new Abstract: Attack Success Rate (ASR) evaluates each jailbreak with a single yes/no label at the end of generation, telling us whether a failure happened but not how it unfolded. Two attacks that produce equally harmful outputs may have followed completely different paths, and ASR cannot tell them apart. We make those hidden paths observable from logits alone. Temporal Logit Observability (TLO) is a training-free diagnostic that watches a compliance-refusal margin during decoding and places each model-attack condition on a calibrated 2D plane. By design, this plane is most informative exactly where ASR is least informative: among attacks that succeed for genuinely different reasons. Across four aligned LLMs and three jailbreak paradigms, attacks with nearly identical ASR land at clearly different points on the plane: the same model can fail through different temporal patterns.

相关公司

暂无数据

相关人物

暂无数据

相关产品

暂无数据