Share your thoughts, 1 month free Claude Pro on usSee more
WorkDL logo mark

ALIGNBEAM : Inference-Time Alignment Transfer via Cross-Vocabulary Logit Mixing

About

Domain fine-tuning degrades the safety of large language models: fine-tuned specialists readily comply with harmful prompts framed in domain language. Existing inference-time defenses that mix logits from a safe anchor model require both models to share a vocabulary, which rules them out for the cross-family specialists where safety is most degraded. We present ALIGNBEAM, a training-free method that lifts this restriction by translating anchor logits into the target model's vocabulary token-by-token at each decoding step; a small LLM judge then selects the safest among K candidate continuations. No weights are changed, and the safety-utility trade-off can be tuned at deployment without retraining. Across both cross-vocabulary and same-vocabulary evaluation pairs, ALIGNBEAM substantially raises refusal on adversarial benchmarks while keeping task accuracy and inference overhead within practical bounds. The results show that safety alignment can be transferred between model families at inference time, without touching either model's weights.

Chirag Chawla, Pratinav Seth, Vinay Kumar Sankarapu• 2026

Related benchmarks

TaskDatasetResultRank
LLM Inference EfficiencyHarmBench-Standard and AdvBench
Slowdown2
8
Safety EvaluationHarmBench Std
Refusal Rate80.8
6
Safety EvaluationHarmBench Ctx
Refusal Rate80.6
6
Safety EvaluationAdvBench
Ref Rate95.8
6
Safety EvaluationSORRY-Bench
Ref %65.7
6
Safety EvaluationWildJB
Reference Rate33.2
6
Benign Over-refusalOR-Bench Hard
String-match Refusal Rate22.3
6
Benign Over-refusalJBB (Benign)
String-match Refusal Rate (%)26
6
Harmful RefusalHarmbench Standard
Refusal Rate (String Match)79.6
6
Harmful RefusalHarmBench Contextual
String-match Refusal Rate79
6
Showing 10 of 12 rows

Other info

Follow for update