{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2024:CPYSSEOTEOUOM6F4FXPC47H6OI","short_pith_number":"pith:CPYSSEOT","schema_version":"1.0","canonical_sha256":"13f12911d323a8e678bc2dde2e7cfe7203aa40c3d76228ac53f7bac11b6d5381","source":{"kind":"arxiv","id":"2411.09003","version":3},"attestation_state":"computed","paper":{"title":"Refusal in LLMs is an Affine Function","license":"http://creativecommons.org/licenses/by/4.0/","headline":"","cross_cats":["cs.CL"],"primary_cat":"cs.LG","authors_text":"Adam Scherlis, Nora Belrose, Thomas Marshall","submitted_at":"2024-11-13T20:12:55Z","abstract_excerpt":"We propose affine concept editing (ACE) as an approach for steering language models' behavior by intervening directly in activations. We begin with an affine decomposition of model activation vectors and show that prior methods for steering model behavior correspond to subsets of terms of this decomposition. We then provide a derivation of ACE and use it to control refusal behavior on ten different models, including Llama 3 70B. ACE combines affine subspace projection and activation addition to reliably control the model's refusal responses across prompt types. We evaluate the results using LL"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2411.09003","kind":"arxiv","version":3},"metadata":{"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.LG","submitted_at":"2024-11-13T20:12:55Z","cross_cats_sorted":["cs.CL"],"title_canon_sha256":"6407d110e8c0f67977aca5c6a4fa7cb958a04e189615764570692396caba0add","abstract_canon_sha256":"29eca4d848c1109b0b4d234d46ec1b153980fcc869ead1203fbb6ee401feb9f6"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T10:06:09.092029Z","signature_b64":"NeyvH4N+eabW4LVziH8UahMq8ZcyRFaKb/DSsO8zqJ40/c/H2T6EsrhRNdP8iCfaiybz0nhBvZqHu++YoInPBA==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"13f12911d323a8e678bc2dde2e7cfe7203aa40c3d76228ac53f7bac11b6d5381","last_reissued_at":"2026-07-05T10:06:09.091491Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T10:06:09.091491Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"Refusal in LLMs is an Affine Function","license":"http://creativecommons.org/licenses/by/4.0/","headline":"","cross_cats":["cs.CL"],"primary_cat":"cs.LG","authors_text":"Adam Scherlis, Nora Belrose, Thomas Marshall","submitted_at":"2024-11-13T20:12:55Z","abstract_excerpt":"We propose affine concept editing (ACE) as an approach for steering language models' behavior by intervening directly in activations. We begin with an affine decomposition of model activation vectors and show that prior methods for steering model behavior correspond to subsets of terms of this decomposition. We then provide a derivation of ACE and use it to control refusal behavior on ten different models, including Llama 3 70B. ACE combines affine subspace projection and activation addition to reliably control the model's refusal responses across prompt types. We evaluate the results using LL"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2411.09003","kind":"arxiv","version":3},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2411.09003/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2411.09003","created_at":"2026-07-05T10:06:09.091585+00:00"},{"alias_kind":"arxiv_version","alias_value":"2411.09003v3","created_at":"2026-07-05T10:06:09.091585+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2411.09003","created_at":"2026-07-05T10:06:09.091585+00:00"},{"alias_kind":"pith_short_12","alias_value":"CPYSSEOTEOUO","created_at":"2026-07-05T10:06:09.091585+00:00"},{"alias_kind":"pith_short_16","alias_value":"CPYSSEOTEOUOM6F4","created_at":"2026-07-05T10:06:09.091585+00:00"},{"alias_kind":"pith_short_8","alias_value":"CPYSSEOT","created_at":"2026-07-05T10:06:09.091585+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":6,"internal_anchor_count":0,"sample":[{"citing_arxiv_id":"2606.04160","citing_title":"Expert-Aware Refusal Steering","ref_index":8,"is_internal_anchor":false},{"citing_arxiv_id":"2606.01196","citing_title":"Low-Resource Safety Failures Are Action Failures, Not Representation Failures","ref_index":33,"is_internal_anchor":false},{"citing_arxiv_id":"2605.17413","citing_title":"Ablating Safety: Mechanisms for Removing Alignment in Language Models for Security Applications","ref_index":23,"is_internal_anchor":false},{"citing_arxiv_id":"2605.01913","citing_title":"RefusalGuard: Geometry-Preserving Fine-Tuning for Safety in LLMs","ref_index":7,"is_internal_anchor":false},{"citing_arxiv_id":"2605.01735","citing_title":"Less is More: Geometric Unlearning for LLMs with Minimal Data Disclosure","ref_index":40,"is_internal_anchor":false},{"citing_arxiv_id":"2605.01913","citing_title":"RefusalGuard: Geometry-Preserving Fine-Tuning for Safety in LLMs","ref_index":8,"is_internal_anchor":false}]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/CPYSSEOTEOUOM6F4FXPC47H6OI","json":"https://pith.science/pith/CPYSSEOTEOUOM6F4FXPC47H6OI.json","graph_json":"https://pith.science/api/pith-number/CPYSSEOTEOUOM6F4FXPC47H6OI/graph.json","events_json":"https://pith.science/api/pith-number/CPYSSEOTEOUOM6F4FXPC47H6OI/events.json","paper":"https://pith.science/paper/CPYSSEOT"},"agent_actions":{"view_html":"https://pith.science/pith/CPYSSEOTEOUOM6F4FXPC47H6OI","download_json":"https://pith.science/pith/CPYSSEOTEOUOM6F4FXPC47H6OI.json","view_paper":"https://pith.science/paper/CPYSSEOT","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2411.09003&json=true","fetch_graph":"https://pith.science/api/pith-number/CPYSSEOTEOUOM6F4FXPC47H6OI/graph.json","fetch_events":"https://pith.science/api/pith-number/CPYSSEOTEOUOM6F4FXPC47H6OI/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/CPYSSEOTEOUOM6F4FXPC47H6OI/action/timestamp_anchor","attest_storage":"https://pith.science/pith/CPYSSEOTEOUOM6F4FXPC47H6OI/action/storage_attestation","attest_author":"https://pith.science/pith/CPYSSEOTEOUOM6F4FXPC47H6OI/action/author_attestation","sign_citation":"https://pith.science/pith/CPYSSEOTEOUOM6F4FXPC47H6OI/action/citation_signature","submit_replication":"https://pith.science/pith/CPYSSEOTEOUOM6F4FXPC47H6OI/action/replication_record"}},"created_at":"2026-07-05T10:06:09.091585+00:00","updated_at":"2026-07-05T10:06:09.091585+00:00"}