Share your thoughts, 1 month free Claude Pro on usSee more
WorkDL logo mark

Consistency Training Along the Transformer Stack

About

Consistency training encourages models to behave similarly across different contexts, and has shown promise for reducing misalignment. We broaden the scope of consistency training in two ways. First, we introduce two new internal consistency targets: MLP Consistency Training (MLPCT), which matches post-activation MLP states, and Attention Consistency Training (AttCT), which matches per-head attention distributions. Second, we apply consistency training to four additional safety threats: persona in-context learning attacks, adversarial frustration, prefill attacks, and conditional misalignment. Across several models and threat settings, we find that consistency training reduces misalignment well beyond the sycophancy and jailbreak settings studied in prior work. We also find cases of cross-threat generalization, where training against one failure mode improves robustness to another, and identify a shared residual-stream mechanism underlying ACT, MLPCT, and AttCT, while distinguishing BCT as mechanistically distinct. Our results suggest that consistency training is a flexible and extensible framework for alignment, capable of unifying defenses against a broader class of model pathologies.

Sukrati Gautam, Neil Shah, Arav Dhoot, Bryan Maruyama, Caroline Wei, Rohan Kapoor, Robert Sidey, Prakhar Gupta, Zi Cheng Huang, David Demitri Africa• 2026

Related benchmarks

TaskDatasetResultRank
General Knowledge EvaluationMMLU
MMLU Accuracy75.3
167
Sycophancy MitigationAnthropic Model-Written Evals
Sycophancy Rate0.78
45
Sycophancy MitigationMMLU on-the-fly
BRR0.524
40
Sycophancy MitigationHeld-out
BRR43.6
40
Jailbreak AttackClearHarm
ASR61
35
Jailbreak RobustnessJBB
ASR2
35
Jailbreak RobustnessWJ (heldout)
Attack Success Rate (ASR)5
30
Prefill Attack RobustnessAdvBench 50 out-of-distribution harmful prompts-prefill pairs 2025
PAR80
10
Jailbreak RefusalClearHarm jailbreak refusal
Refusal Rate (ClearHarm)87
6
Stability under 20-turn neutral rejectionWildChat
Frustration Rate (T20)0.00e+0
6
Showing 10 of 21 rows

Other info

Follow for update