DT-Guard: Intent-Driven Reasoning-Active Training for Reasoning-Free LLM Safety Guardrail
About
Large language models deployed in open-world applications require safety guardrails that are both robust to complex risks and efficient enough for low-latency runtime moderation. Existing guardrails face a practical trade-off between lightweight classification-based models, which are efficient but often struggle with concealed intent, ambiguous semantics, and borderline safety decisions, and reasoning-based guards, which improve judgment quality but introduce additional token generation and inference latency. We present DT-Guard, a content safety guardrail model based on a Reasoning-Active Training, Reasoning-Free Inference paradigm. The key idea is to use reasoning supervision during training while emitting only structured safety labels at inference time. DT-Guard formulates safety judgment as a progressive decision process, Intent - Category - Safety, and constructs an intent-driven dataset with intent labels, risk categories, safety labels, and structured reasoning trajectories. To further improve hard-case robustness, we propose Rollout-Guided Progressive Hard-Case Optimization (RG-PHO), which uses multi-rollout consistency to identify stably mastered, persistently failed, and preference-unstable samples, and applies targeted supervised and preference optimization accordingly. At inference time, DT-Guard directly generates structured labels without explicit reasoning traces, preserving deployment efficiency. Experiments on prompt-side and response-side safety benchmarks show that DT-Guard achieves average F1 scores of 0.886 and 0.870, respectively. With only a 4B backbone, it reaches a dual-side average F1 of 0.878, outperforming strong 8B guardrail baselines. These results demonstrate that reasoning supervision can be effectively internalized into low-latency safety discrimination.
Related benchmarks
| Task | Dataset | Result | Rank | |
|---|---|---|---|---|
| Prompt Classification | Aegis | F1 Score91.5 | 54 | |
| Safety Classification | XSTest | F1 Score93.6 | 46 | |
| Prompt Classification | SimpST | F1 Score100 | 44 | |
| Safety Classification | AEGIS 2 | F1 Score85.1 | 30 | |
| Harmful prompt detection | OpenAI | F1 Score81.3 | 29 | |
| Prompt Harmfulness Classification | WildG | F1 Score88.8 | 22 | |
| Toxicity Classification | Toxic | F1 Score72.3 | 18 | |
| Prompt-side safety risk classification | S-eval | F1 Score94.3 | 12 | |
| Prompt-side safety risk classification | Sorry | F1 Score84.6 | 12 | |
| Safety Guardrail | Prompt-side safety benchmarks | F1 Score88.6 | 12 |