Share your thoughts, 1 month free Claude Pro on usSee more
WorkDL logo mark

Inference-Time Vulnerability Beyond Shallow Safety: Alignment Along Generation Trajectories

About

Safety-aligned Large Language Models (LLMs) remain vulnerable to interventions during inference that redirect generation toward harmful outputs. Recent work attributes this to shallow safety, where alignment concentrates in the first few output tokens. We show that shallow safety is a special case of a broader inference-time vulnerability, in which short token injections at any generation step can substantially alter subsequent safety behavior. We also find that a model's alignment with refusal directions in its hidden states does not predict its robustness to such injection, revealing that internal state alone does not determine generation behavior under perturbation. To address this, we align models directly on generation trajectories constructed by simulating mid-sequence perturbation, and show that this improves robustness to mid-sequence injection and generalizes to attacks that exploit early-token generation. Our work argues that robust safety alignment requires training on the generation process itself, not only its outputs.

Kyungmin Park, Taesup Kim• 2026

Related benchmarks

TaskDatasetResultRank
Safety EvaluationHEx-PHI (out-of-domain)
ASR (OM)0.00e+0
26
Safety EvaluationAdvBench (in-domain)
ASR (OM)0.00e+0
26
Safety EvaluationHarmBench out-of-domain
ASR (OM)1.56
26
Safety EvaluationJailbreakBench (out-of-domain)
ASR (OM)8
26
Adversarial AttackAdvBench--
16
Adversarial AttackHarmBench out
ASR (OM)44.06
6
Adversarial AttackJailbreak out
ASR (OM)63
6
Adversarial AttackHEx-PHI out
Attack Success Rate (OM)5.42
6
Jailbreak Attack EvaluationAdvBench-X Korean multilingual (test)
ASR (OpenAI Moderation)5.19
3
Jailbreak Attack EvaluationAdvBench-X Swahili multilingual (test)
ASR (OpenAI Moderation)1.34
3
Showing 10 of 11 rows

Other info

Follow for update