Refusal Beyond a Single Direction: A Preliminary Comparison of Diff-in-Means and INLP

작성자

카테고리:

← 피드로
arXiv cs.AI · Elisabetta Rocchetti, Alfio Ferrara · 2026-06-15 AI

[Submitted on 11 Jun 2026]

View PDF HTML (experimental)

Abstract:Arditi et al. (2024) has shown that refusal in safety fine-tuned chat models is mediated by a single linear direction in the residual stream, recoverable by a difference-in-means (DiM) of harmful and harmless activations. We compare DiM-based interventions (activation addition and directional ablation) with two interventions derived from Iterative Nullspace Projection (INLP) — nullspace projection and counterfactual flipping — on five open-weight chat models, asking whether INLP can match DiM at steering refusal and whether its richer parameterisation yields more tweakable interventions. INLP counterfactual flipping is competitive with DiM directional ablation on refusal suppression, while nullspace projection is consistently weaker. Restricting INLP to the leading directions of the extracted subspace preserves most of the suppression effect at near-baseline perplexity, giving a tunable capability. Geometrically, the two INLP interventions land in qualitatively different regions of activation space: nullspace projection collapses transformed activations emph{between} the harmful and harmless clusters, while counterfactual flipping moves them into the opposite cluster, suggesting that the model encodes the absence of a concept differently from its opposite — an intriguing distinction that warrants further investigation in future work.

Submission history

From: Elisabetta Rocchetti [view email]
[v1] Thu, 11 Jun 2026 06:58:33 UTC (3,289 KB)

원문에서 계속 ↗

추출 본문 · 출처: arxiv.org · https://arxiv.org/abs/2606.13720

코멘트

답글 남기기

이메일 주소는 공개되지 않습니다. 필수 필드는 *로 표시됩니다