Differentiated Directional Intervention A Framework for Evading LLM Safety Alignment

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Zhang, Peng, Sun, Peijie
Format: Preprint
Published: 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866909919138021376
author Zhang, Peng
Sun, Peijie
author_facet Zhang, Peng
Sun, Peijie
contents Safety alignment instills in Large Language Models (LLMs) a critical capacity to refuse malicious requests. Prior works have modeled this refusal mechanism as a single linear direction in the activation space. We posit that this is an oversimplification that conflates two functionally distinct neural processes: the detection of harm and the execution of a refusal. In this work, we deconstruct this single representation into a Harm Detection Direction and a Refusal Execution Direction. Leveraging this fine-grained model, we introduce Differentiated Bi-Directional Intervention (DBDI), a new white-box framework that precisely neutralizes the safety alignment at critical layer. DBDI applies adaptive projection nullification to the refusal execution direction while suppressing the harm detection direction via direct steering. Extensive experiments demonstrate that DBDI outperforms prominent jailbreaking methods, achieving up to a 97.88\% attack success rate on models such as Llama-2. By providing a more granular and mechanistic framework, our work offers a new direction for the in-depth understanding of LLM safety alignment.
format Preprint
id arxiv_https___arxiv_org_abs_2511_06852
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Differentiated Directional Intervention A Framework for Evading LLM Safety Alignment
Zhang, Peng
Sun, Peijie
Cryptography and Security
Artificial Intelligence
Machine Learning
Software Engineering
Safety alignment instills in Large Language Models (LLMs) a critical capacity to refuse malicious requests. Prior works have modeled this refusal mechanism as a single linear direction in the activation space. We posit that this is an oversimplification that conflates two functionally distinct neural processes: the detection of harm and the execution of a refusal. In this work, we deconstruct this single representation into a Harm Detection Direction and a Refusal Execution Direction. Leveraging this fine-grained model, we introduce Differentiated Bi-Directional Intervention (DBDI), a new white-box framework that precisely neutralizes the safety alignment at critical layer. DBDI applies adaptive projection nullification to the refusal execution direction while suppressing the harm detection direction via direct steering. Extensive experiments demonstrate that DBDI outperforms prominent jailbreaking methods, achieving up to a 97.88\% attack success rate on models such as Llama-2. By providing a more granular and mechanistic framework, our work offers a new direction for the in-depth understanding of LLM safety alignment.
title Differentiated Directional Intervention A Framework for Evading LLM Safety Alignment
topic Cryptography and Security
Artificial Intelligence
Machine Learning
Software Engineering
url https://arxiv.org/abs/2511.06852