Pith. sign in
Pith Number

pith:KIOBQZTC

pith:2026:KIOBQZTCK252DPBZ4XBSY7P6FQ
not attested not anchored not stored refs resolved

Before the Last Token: Diagnosing Final-Token Safety Probe Failures

Shravan Doda

Final-token safety probes miss jailbreak evidence spread across earlier tokens, but a PCA-HMM model on prefill trajectories recovers many such cases without high false positives.

arxiv:2605.12726 v1 · 2026-05-12 · cs.LG

Add to your LaTeX paper
\usepackage{pith}
\pithnumber{KIOBQZTCK252DPBZ4XBSY7P6FQ}

Prints a linked badge after your title and injects PDF metadata. Compiles on arXiv. Learn more · Embed verified badge

Record completeness

1 Bitcoin timestamp
2 Internet Archive
3 Author claim open · sign in to claim
4 Citations open
5 Replications open
Portable graph bundle live · download bundle · merged state
The bundle contains the canonical record plus signed events. A mirror can host it anywhere and recompute the same current state with the deterministic merge algorithm.

Claims

C1strongest claim

A simple PCA-HMM trajectory model, trained only on the same clean split, recovers many final-token misses from user-content prefill trajectories without the catastrophic false-positive behavior of naive token pooling.

C2weakest assumption

That subspace analyses accurately identify the directions missed by the probe and that the PCA-HMM model trained on clean prompts generalizes to recover jailbreak cases without introducing new failure modes.

C3one line summary

Final-token probes miss distributed unsafe evidence in jailbreaks, but a PCA-HMM model on prefill trajectories recovers many misses without naive pooling's false positives.

References

16 extracted · 16 resolved · 7 Pith anchors

[1] Refusal in Language Models Is Mediated by a Single Direction · arXiv:2406.11717
[2] Safeswitch: Steering unsafe llm behavior via internal activation signals
[3] Lin, Z., Yang, J., Qiu, Y ., Guo, H., Bao, Y ., and Guan, Y · arXiv:2310.06825
[4] org/abs/2511.14195
[5] TrajGuard: Streaming Hidden-state Trajectory Detection for Decoding-time Jailbreak Defense · arXiv:2604.07727
Receipt and verification
First computed 2026-05-18T03:09:49.321911Z
Builder pith-number-builder-2026-05-17-v1
Signature Pith Ed25519 (pith-v1-2026-05) · public key
Schema pith-number/v1.0

Canonical hash

521c18666256bba1bc39e5c32c7dfe2c20c2c3843ec55fa1317115eb92f9f7d7

Aliases

arxiv: 2605.12726 · arxiv_version: 2605.12726v1 · doi: 10.48550/arxiv.2605.12726 · pith_short_12: KIOBQZTCK252 · pith_short_16: KIOBQZTCK252DPBZ · pith_short_8: KIOBQZTC
Agent API
Verify this Pith Number yourself
curl -sH 'Accept: application/ld+json' https://pith.science/pith/KIOBQZTCK252DPBZ4XBSY7P6FQ \
  | jq -c '.canonical_record' \
  | python3 -c "import sys,json,hashlib; b=json.dumps(json.loads(sys.stdin.read()), sort_keys=True, separators=(',',':'), ensure_ascii=False).encode(); print(hashlib.sha256(b).hexdigest())"
# expect: 521c18666256bba1bc39e5c32c7dfe2c20c2c3843ec55fa1317115eb92f9f7d7
Canonical record JSON
{
  "metadata": {
    "abstract_canon_sha256": "2cc9767e40cfc68be3d27a2a0fecf791b522829c07d9270ddcf669032f24201c",
    "cross_cats_sorted": [],
    "license": "http://creativecommons.org/licenses/by/4.0/",
    "primary_cat": "cs.LG",
    "submitted_at": "2026-05-12T20:30:24Z",
    "title_canon_sha256": "7f878d548d0a924a9b6b0a69ccd24f295e112830e1b2eaa51cc49b99a58870f8"
  },
  "schema_version": "1.0",
  "source": {
    "id": "2605.12726",
    "kind": "arxiv",
    "version": 1
  }
}