Step-Wise Refusal Dynamics in Autoregressive and Diffusion Language Models

Fuente: arXiv
Enregistré dans:
Détails bibliographiques
Auteurs principaux: Rahimi, Eliron, Hirshel, Elad, Himelstein, Rom, LeVi, Amit, Mendelson, Avi, Baskin, Chaim
Format: Preprint
Publié: 2026
Sujets:
Accès en ligne:
Tags: Ajouter un tag
Pas de tags, Soyez le premier à ajouter un tag!
_version_ 1866912886870245376
author Rahimi, Eliron
Hirshel, Elad
Himelstein, Rom
LeVi, Amit
Mendelson, Avi
Baskin, Chaim
author_facet Rahimi, Eliron
Hirshel, Elad
Himelstein, Rom
LeVi, Amit
Mendelson, Avi
Baskin, Chaim
contents Diffusion language models (DLMs) have recently emerged as a promising alternative to autoregressive (AR) models, offering parallel decoding and controllable sampling dynamics while achieving competitive generation quality at scale. Despite this progress, the role of sampling mechanisms in shaping refusal behavior and jailbreak robustness remains poorly understood. In this work, we present a fundamental analytical framework for step-wise refusal dynamics, enabling comparison between AR and diffusion sampling. Our analysis reveals that the sampling strategy itself plays a central role in safety behavior, as a factor distinct from the underlying learned representations. Motivated by this analysis, we introduce the Step-Wise Refusal Internal Dynamics (SRI) signal, which supports interpretability and improved safety for both AR and DLMs. We demonstrate that the geometric structure of SRI captures internal recovery dynamics, and identifies anomalous behavior in harmful generations as cases of \emph{incomplete internal recovery} that are not observable at the text level. This structure enables lightweight inference-time detectors that generalize to unseen attacks while matching or outperforming existing defenses with over $100\times$ lower inference overhead.
format Preprint
id arxiv_https___arxiv_org_abs_2602_02600
institution arXiv
publishDate 2026
record_format arxiv
spellingShingle Step-Wise Refusal Dynamics in Autoregressive and Diffusion Language Models
Rahimi, Eliron
Hirshel, Elad
Himelstein, Rom
LeVi, Amit
Mendelson, Avi
Baskin, Chaim
Machine Learning
Artificial Intelligence
Diffusion language models (DLMs) have recently emerged as a promising alternative to autoregressive (AR) models, offering parallel decoding and controllable sampling dynamics while achieving competitive generation quality at scale. Despite this progress, the role of sampling mechanisms in shaping refusal behavior and jailbreak robustness remains poorly understood. In this work, we present a fundamental analytical framework for step-wise refusal dynamics, enabling comparison between AR and diffusion sampling. Our analysis reveals that the sampling strategy itself plays a central role in safety behavior, as a factor distinct from the underlying learned representations. Motivated by this analysis, we introduce the Step-Wise Refusal Internal Dynamics (SRI) signal, which supports interpretability and improved safety for both AR and DLMs. We demonstrate that the geometric structure of SRI captures internal recovery dynamics, and identifies anomalous behavior in harmful generations as cases of \emph{incomplete internal recovery} that are not observable at the text level. This structure enables lightweight inference-time detectors that generalize to unseen attacks while matching or outperforming existing defenses with over $100\times$ lower inference overhead.
title Step-Wise Refusal Dynamics in Autoregressive and Diffusion Language Models
topic Machine Learning
Artificial Intelligence
url https://arxiv.org/abs/2602.02600