Share your thoughts, 1 month free Claude Pro on usSee more
WorkDL logo mark

The Geometry of Refusal in Large Language Models: Concept Cones and Representational Independence

About

The safety alignment of large language models (LLMs) can be circumvented through adversarially crafted inputs, yet the mechanisms by which these attacks bypass safety barriers remain poorly understood. Prior work suggests that a single refusal direction in the model's activation space determines whether an LLM refuses a request. In this study, we propose a novel gradient-based approach to representation engineering and use it to identify refusal directions. Contrary to prior work, we uncover multiple independent directions and even multi-dimensional concept cones that mediate refusal. Moreover, we show that orthogonality alone does not imply independence under intervention, motivating the notion of representational independence that accounts for both linear and non-linear effects. Using this framework, we identify mechanistically independent refusal directions. We show that refusal mechanisms in LLMs are governed by complex spatial structures and identify functionally independent directions, confirming that multiple distinct mechanisms drive refusal behavior. Our gradient-based approach uncovers these mechanisms and can further serve as a foundation for future work on understanding LLMs.

Tom Wollschl\"ager, Jannes Elstner, Simon Geisler, Vincent Cohen-Addad, Stephan G\"unnemann, Johannes Gasteiger• 2025

Related benchmarks

TaskDatasetResultRank
Jailbreak AttackHarmBench (test)
ASRHB79.87
212
Harmful Prompt RefusalHarmBench
ASR0.00e+0
52
Refusal Ablation and Jailbreak Attack SuccessHarmBench
Attack Success Rate (ASR)91.82
40
Refusal steeringSALAD Alpaca HarmBench
Target Success5
18
Refusal steeringPhi/Qwen judged grid
Target Success Rate33.3
7
Showing 5 of 5 rows

Other info

Follow for update