{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2025:3453PNDKVN7J4PEB7ZV2EO6R4E","short_pith_number":"pith:3453PNDK","schema_version":"1.0","canonical_sha256":"df3bb7b46aab7e9e3c81fe6ba23bd1e10a3a568d0cee3a6b544d9c22a88ee49c","source":{"kind":"arxiv","id":"2508.09224","version":1},"attestation_state":"computed","paper":{"title":"From Hard Refusals to Safe-Completions: Toward Output-Centric Safety Training","license":"http://creativecommons.org/licenses/by/4.0/","headline":"","cross_cats":["cs.AI","cs.CL"],"primary_cat":"cs.CY","authors_text":"Alec Helyar, Alex Beutel, Andrea Vallone, Anna-Luisa Brakman, Saachi Jain, Tina Sriskandarajah, Yuan Yuan","submitted_at":"2025-08-12T00:18:23Z","abstract_excerpt":"Large Language Models used in ChatGPT have traditionally been trained to learn a refusal boundary: depending on the user's intent, the model is taught to either fully comply or outright refuse. While this is a strong mitigation for explicitly malicious prompts, focusing safety training on refusals can lead to brittleness for prompts with obscured user intent. Binary refusal boundaries are especially ill-suited for dual-use cases (such as biology or cybersecurity), where a user request can be answered safely at a high level, but in some cases can lead to malicious uplift if sufficiently detaile"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2508.09224","kind":"arxiv","version":1},"metadata":{"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CY","submitted_at":"2025-08-12T00:18:23Z","cross_cats_sorted":["cs.AI","cs.CL"],"title_canon_sha256":"30db5d38d8c7f97e956ebc2ef1b54eca28262a7ed36f7f4d1a2d1648e115ff05","abstract_canon_sha256":"4f169afb3a67448d3e7117fbde912c8ae401cab310451836f1d2f28307b32757"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T11:53:10.471080Z","signature_b64":"fAE5CZR3VvxJ4h9VmO4GFgMFfqEQM80L+cDUyk7hV30rpQwrT6XKhKbdNv7XefVg+oEVwigEbxdcuNu+d+gMBg==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"df3bb7b46aab7e9e3c81fe6ba23bd1e10a3a568d0cee3a6b544d9c22a88ee49c","last_reissued_at":"2026-07-05T11:53:10.470594Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T11:53:10.470594Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"From Hard Refusals to Safe-Completions: Toward Output-Centric Safety Training","license":"http://creativecommons.org/licenses/by/4.0/","headline":"","cross_cats":["cs.AI","cs.CL"],"primary_cat":"cs.CY","authors_text":"Alec Helyar, Alex Beutel, Andrea Vallone, Anna-Luisa Brakman, Saachi Jain, Tina Sriskandarajah, Yuan Yuan","submitted_at":"2025-08-12T00:18:23Z","abstract_excerpt":"Large Language Models used in ChatGPT have traditionally been trained to learn a refusal boundary: depending on the user's intent, the model is taught to either fully comply or outright refuse. While this is a strong mitigation for explicitly malicious prompts, focusing safety training on refusals can lead to brittleness for prompts with obscured user intent. Binary refusal boundaries are especially ill-suited for dual-use cases (such as biology or cybersecurity), where a user request can be answered safely at a high level, but in some cases can lead to malicious uplift if sufficiently detaile"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2508.09224","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2508.09224/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2508.09224","created_at":"2026-07-05T11:53:10.470656+00:00"},{"alias_kind":"arxiv_version","alias_value":"2508.09224v1","created_at":"2026-07-05T11:53:10.470656+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2508.09224","created_at":"2026-07-05T11:53:10.470656+00:00"},{"alias_kind":"pith_short_12","alias_value":"3453PNDKVN7J","created_at":"2026-07-05T11:53:10.470656+00:00"},{"alias_kind":"pith_short_16","alias_value":"3453PNDKVN7J4PEB","created_at":"2026-07-05T11:53:10.470656+00:00"},{"alias_kind":"pith_short_8","alias_value":"3453PNDK","created_at":"2026-07-05T11:53:10.470656+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":15,"internal_anchor_count":0,"sample":[{"citing_arxiv_id":"2607.02047","citing_title":"OpenSafeIntent: Evaluating Intent-Calibrated Safe Completion Across Dual-Use Prompt Sets","ref_index":5,"is_internal_anchor":false},{"citing_arxiv_id":"2606.03648","citing_title":"Safety Measurements for Fine-tuned LLMs Should be Grounded in Capability","ref_index":20,"is_internal_anchor":false},{"citing_arxiv_id":"2606.02423","citing_title":"Investigating and Alleviating Harm Amplification in LLM Interactions","ref_index":24,"is_internal_anchor":false},{"citing_arxiv_id":"2605.31381","citing_title":"LLM Judges Inconsistently Disagree Across Safety Criteria and Harm Categories","ref_index":4,"is_internal_anchor":false},{"citing_arxiv_id":"2606.30661","citing_title":"Understanding Censorship in Large Language Models: From Mechanisms to Governance","ref_index":42,"is_internal_anchor":false},{"citing_arxiv_id":"2605.22771","citing_title":"Reducing Political Manipulation with Consistency Training","ref_index":40,"is_internal_anchor":false},{"citing_arxiv_id":"2605.22771","citing_title":"Reducing Political Manipulation with Consistency Training","ref_index":40,"is_internal_anchor":false},{"citing_arxiv_id":"2509.09870","citing_title":"Vibe Check: Understanding the Effects of LLM-Based Conversational Agents' Personality and Alignment on User Perceptions in Goal-Oriented Tasks","ref_index":114,"is_internal_anchor":false},{"citing_arxiv_id":"2509.26238","citing_title":"Beyond Linear Probes: Dynamic Safety Monitoring for Language Models","ref_index":63,"is_internal_anchor":false},{"citing_arxiv_id":"2605.08930","citing_title":"Internalizing Safety Understanding in Large Reasoning Models via Verification","ref_index":26,"is_internal_anchor":false},{"citing_arxiv_id":"2604.24082","citing_title":"Jailbreaking Frontier Foundation Models Through Intention Deception","ref_index":22,"is_internal_anchor":false},{"citing_arxiv_id":"2605.05678","citing_title":"Chain of Risk: Safety Failures in Large Reasoning Models and Mitigation via Adaptive Multi-Principle Steering","ref_index":11,"is_internal_anchor":false},{"citing_arxiv_id":"2604.07709","citing_title":"IatroBench: Pre-Registered Evidence of Iatrogenic Harm from AI Safety Measures","ref_index":24,"is_internal_anchor":false},{"citing_arxiv_id":"2604.18463","citing_title":"Using large language models for embodied planning introduces systematic safety risks","ref_index":83,"is_internal_anchor":false},{"citing_arxiv_id":"2604.17299","citing_title":"Cat-DPO: Category-Adaptive Safety Alignment","ref_index":25,"is_internal_anchor":false}]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/3453PNDKVN7J4PEB7ZV2EO6R4E","json":"https://pith.science/pith/3453PNDKVN7J4PEB7ZV2EO6R4E.json","graph_json":"https://pith.science/api/pith-number/3453PNDKVN7J4PEB7ZV2EO6R4E/graph.json","events_json":"https://pith.science/api/pith-number/3453PNDKVN7J4PEB7ZV2EO6R4E/events.json","paper":"https://pith.science/paper/3453PNDK"},"agent_actions":{"view_html":"https://pith.science/pith/3453PNDKVN7J4PEB7ZV2EO6R4E","download_json":"https://pith.science/pith/3453PNDKVN7J4PEB7ZV2EO6R4E.json","view_paper":"https://pith.science/paper/3453PNDK","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2508.09224&json=true","fetch_graph":"https://pith.science/api/pith-number/3453PNDKVN7J4PEB7ZV2EO6R4E/graph.json","fetch_events":"https://pith.science/api/pith-number/3453PNDKVN7J4PEB7ZV2EO6R4E/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/3453PNDKVN7J4PEB7ZV2EO6R4E/action/timestamp_anchor","attest_storage":"https://pith.science/pith/3453PNDKVN7J4PEB7ZV2EO6R4E/action/storage_attestation","attest_author":"https://pith.science/pith/3453PNDKVN7J4PEB7ZV2EO6R4E/action/author_attestation","sign_citation":"https://pith.science/pith/3453PNDKVN7J4PEB7ZV2EO6R4E/action/citation_signature","submit_replication":"https://pith.science/pith/3453PNDKVN7J4PEB7ZV2EO6R4E/action/replication_record"}},"created_at":"2026-07-05T11:53:10.470656+00:00","updated_at":"2026-07-05T11:53:10.470656+00:00"}