Refusal is linearly decodable from intermediate LLM activations, enabling a probe-guided AutoDAN variant that matches attack success rates while cutting search time by up to 72%.
These are the Activation Datasetsused for the target classi- fier training (as described in Section 4)
1 Pith paper cite this work. Polarity classification is still indexing.
1
Pith paper citing it
fields
cs.AI 1years
2026 1verdicts
UNVERDICTED 1representative citing papers
citing papers explorer
-
Refusal Before Decoding: Detecting and Exploiting Refusal Signals in Intermediate LLM Activations
Refusal is linearly decodable from intermediate LLM activations, enabling a probe-guided AutoDAN variant that matches attack success rates while cutting search time by up to 72%.