pith:XZY4ZXL3
Tracing the Dynamics of Refusal: Exploiting Latent Refusal Trajectories for Robust Jailbreak Detection
Refusal in language models follows a persistent upstream trajectory that remains detectable even when attacks suppress the final output.
arxiv:2605.02958 v2 · 2026-05-02 · cs.CR · cs.AI · cs.CL · cs.LG
Add to your LaTeX paper
\usepackage{pith}
\pithnumber{XZY4ZXL3XZ2D2LICCL4JKYQFZE}
Prints a linked badge after your title and injects PDF metadata. Compiles on arXiv. Learn more · Embed verified badge
Record completeness
Claims
SALO effectively recovers defense capabilities against forced-decoding attacks, improving detection rates from ~0% to >90% where methods relying on terminal states perform poorly.
That the refusal trajectory uncovered by causal tracing is a stable, generalizable signature rather than an artifact of the specific models, prompts, or attack implementations tested.
Refusal in LLMs leaves a detectable upstream trajectory that SALO exploits to raise jailbreak detection from near zero to over 90 percent even under forced-decoding attacks.
Receipt and verification
| First computed | 2026-05-27T02:05:20.995842Z |
|---|---|
| Builder | pith-number-builder-2026-05-17-v1 |
| Signature | Pith Ed25519
(pith-v1-2026-05) · public key |
| Schema | pith-number/v1.0 |
Canonical hash
be71ccdd7bbe743d2d0212f8956205c917e64bd2b553330318ae754b2634ae0a
Aliases
· · · · ·Agent API
Verify this Pith Number yourself
curl -sH 'Accept: application/ld+json' https://pith.science/pith/XZY4ZXL3XZ2D2LICCL4JKYQFZE \
| jq -c '.canonical_record' \
| python3 -c "import sys,json,hashlib; b=json.dumps(json.loads(sys.stdin.read()), sort_keys=True, separators=(',',':'), ensure_ascii=False).encode(); print(hashlib.sha256(b).hexdigest())"
# expect: be71ccdd7bbe743d2d0212f8956205c917e64bd2b553330318ae754b2634ae0a
Canonical record JSON
{
"metadata": {
"abstract_canon_sha256": "cf1283eaae0d3c3f8260207ad798c8cb1550b8dc42bd189aacf550e82cc713e6",
"cross_cats_sorted": [
"cs.AI",
"cs.CL",
"cs.LG"
],
"license": "http://creativecommons.org/licenses/by/4.0/",
"primary_cat": "cs.CR",
"submitted_at": "2026-05-02T14:56:37Z",
"title_canon_sha256": "7a717b3cf54a281cb8222adc6d592e0a68a6c5804b8f43693ec264675e837ec2"
},
"schema_version": "1.0",
"source": {
"id": "2605.02958",
"kind": "arxiv",
"version": 2
}
}