惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

H
Help Net Security
T
ThreatConnect
SecWiki News
SecWiki News
F
Future of Privacy Forum
AWS News Blog
AWS News Blog
C
Cisco Blogs
A
Arctic Wolf
Vercel News
Vercel News
The GitHub Blog
The GitHub Blog
Scott Helme
Scott Helme
V
V2EX
博客园 - 叶小钗
阮一峰的网络日志
阮一峰的网络日志
K
Kaspersky official blog
G
Google Developers Blog
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
P
Privacy International News Feed
C
Cyber Attacks, Cyber Crime and Cyber Security
N
News | PayPal Newsroom
Schneier on Security
Schneier on Security
NISL@THU
NISL@THU
Microsoft Azure Blog
Microsoft Azure Blog
量子位
The Hacker News
The Hacker News
Stack Overflow Blog
Stack Overflow Blog
Security Latest
Security Latest
M
Microsoft Research Blog - Microsoft Research
Google Online Security Blog
Google Online Security Blog
博客园_首页
C
CXSECURITY Database RSS Feed - CXSecurity.com
I
InfoQ
Google DeepMind News
Google DeepMind News
Y
Y Combinator Blog
The Cloudflare Blog
Microsoft Security Blog
Microsoft Security Blog
Martin Fowler
Martin Fowler
Cisco Talos Blog
Cisco Talos Blog
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
T
Troy Hunt's Blog
F
Fox-IT International blog
S
Security @ Cisco Blogs
博客园 - 司徒正美
cs.CV updates on arXiv.org
cs.CV updates on arXiv.org
C
Comments on: Blog
Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
L
LINUX DO - 最新话题
GbyAI
GbyAI
Project Zero
Project Zero
腾讯CDC
T
Tailwind CSS Blog

cs.LG updates on arXiv.org

LLMTabBench: Evaluating LLMs on Binary Tabular Classification From Zero to Few Shots CONF-KV: Confidence-Aware KV Cache Eviction with Mixed-Precision Storage for Long-Horizon LLM What Are We Actually Decoding? Source Attribution for Non-Invasive Brain-to-Language Retrieval Trajectory-Based Difficulty Scoring for Reliable Learning on Tabular Data CAffNet: Hard Constraint-Affine Neural Networks CurveRL: Principled Distribution-Aware Context Reweighting for LLM Reasoning Synheart Capacity: A Theory-Driven Physiological Representation of Cognitive Capacity Dynamics from Wearable Signals Treatment Effect Estimation with Differentiated Networked Effect on Graph Data Spectral Probe-Circuits: A Three-Step Recipe for Identifying Attention-Head Circuits in Pretrained Transformers RL with Learnable Textual Feedback: A Bilevel Approach Private Adaptive Covariance Estimation via Gaussian Graphical Models Faithfulness as Information Flow: Evaluating and Training Faithful Chain-of-Thought Reasoning LLM-AutoSciLab: Closed-Loop Scientific Discovery via Active Experimentation with LLMs MindAlign: Bridging EEG, Vision, and Language for Zero-Shot Visual Decoding CSP-Atlas: Concept-Specific Neural Circuits in a Sparse Python Transformer Streaming Reinforcement Learning under Partial Observability with Real-Time Recurrent Learning ChainLearn: A Blockchain-Based Capacity-Aware Framework for Federated Ensemble Learning Federated Learning over Human-Body Communication for On-Body Edge Intelligence: A Survey, Taxonomy, and BODYFED-HBC Scheduling Vignette Aligning Molecular Graph Explanations with Chemical Identity via InChIfied Invariants Parameter Efficient Multi-Class Intelligent Scheduling for Multimodal Online Distributed Industrial Anomaly Detection Evolving Robustness--Exploration Trade-off in Online Reinforcement Learning via Quantile Bayesian Risk MDPs Towards Verifiable Transformers: Solver-Checkable Circuit Explanations Batch Normalization Amplifies Memorization and Privacy Risks Representation-Guided Discrete Molecular Graph Retrosynthesis Rethinking Continual Anomaly Detection on the Edge: Benchmarking Under Realistic Industrial Conditions Extracting Training Data from Diffusion Language Models via Infilling Filtered Posterior Mean Collections: A Unified Framework for Analytical Models of Diffusion Generalization Cascade-KDE: Robust Time-Series Restoration under Out-of-Distribution Impulse Corruptions A lift for input-convex neural network training High-fidelity Modeling of Full-scale Pressurized Water Reactor Flow Fields for Machine Learning Applications Active Learning for Stochastic Contextual Linear Bandits The Perception-Physics Paradox: Probing Scientific Alignment with TC-Bench Mixture of Complementary Agents for Robust LLM Ensemble LAPLEX: The FFT of Learnable Laplace Kernels CAFD: Concept-Aware DNN Fault Detection using VLMs Position: AI for Science Should Treat Measurement-to-Dataset Pipelines as Inference Components Discovering Lexical Gaps Using Embeddings from Multilingual LLMs Beyond Generative Priors: Minority Sampling with JEPA-Guided Diffusion An Effective-Rank Audit of Alignment-Induced Activation Shifts: Confound Control, Constructive Calibration, and Limits Truthful Online Preference Aggregation for LLM Fine-Tuning in Mobile Crowdsourcing Beyond the Aggregation Dilemma: Prior-Retaining Decoupled Learning for Multimodal Graphs AvAtar: Learning to Align via Active Optimal Transport PrivFusion: A Privacy-preserving Multi-Agent Framework for Harmonizing Distributed Datasets Overcoming "Physics Shock" in Earth Observation A Heteroscedastic Uncertainty Framework for PINN-based Flood Inference IterInject: Indirect Prompt Injection Against LLM Agents via Feedback-Guided Iterative Optimization Muon in Vision Transformers: Optimizer-Recipe Interactions and Gradient Spectra Measuring the Depth of LLM Unlearning via Activation Patching TUBE: Tangent Upper Bound on Evidence for Discrete Diffusion Language Models Hermite-NGP: Gradient-Augmented Hash Encoding for Learning PDEs WINO: A Weak-Form Physics Informed Neural Operator for Hyperelasticity on Variable Domains Agent-ToM: Learning to Monitor Autonomous LLM Agents via Theory-of-Mind Reasoning Generative OOD-regularized Model-based Policy Optimization Reinforcement Learning for Reachability: Guaranteeing Asymptotic Optimality ChaosBench-Logic v2: Evaluating LLM Logical Reasoning over Dynamical Systems at Scale Optimizing Digital Therapeutic Interventions: Online Learning under Endogenous Adherence Algometrics: Forecasting Under Algorithmic Feedback Interdomain Attention: Beyond Token-Level Key-Value Memory GEESE: Genotype-aware End-to-End Spatio-temporal Embedding for Behavioral Phenotyping LLMs Show No Signs Of Individuated Metacognition Not All Transitions Matter: Evidence from PPO ChainzRule: Sample-Efficient, Robust Deep Learning Across Tabular, NLP, and Vision Tasks A Unified Python Framework for Direct PPO-based Control of AHUs with Economizer Logic and CO2-Constrained Ventilation Balancing Fairness, Privacy, and Accuracy: A Multitask Adversarial Framework for Centralized Data-Driven Systems Deep ZakaiJ: Structured Filtering for Jump-Diffusion Time Series Forecasting Polymorphism Is Rotation: Operational Mechanistic Interpretability from a Two-Layer Transformer to Pythia-70m WLNO: Wavelet-Laplace Neural Operator for Solving Partial Differential Equations SemanticZip: A Pilot Framework for Lossy Text Compression with LLMs as Semantic Decompressors Zeroth-Order Nonconvex Nonsmooth Optimization with Heavy-Tailed Noise Temporal Concept Drift in Legal Judgment Prediction: Neural Baselines Across Three Epochs of Ukrainian Court Decisions Beyond Fixed Points: Superpolynomial Capacity of Asymmetric Hopfield Networks Lake Detection and Water Quality Estimation in Sentinel-2 Data Bilevel Optimization of Synthetic Trajectories for Multi-Turn LLM Fine-Tuning Verified SHAP: Provable Bounds for Exact Shapley Values of Neural Networks Hardware-Aware Federated Learning for Speech Emotion Recognition Generative Representation Learning on Hyper-relational Knowledge Graphs via Masked Discrete Diffusion On the Stability and Realizability of Recurrent Polynomial Surrogate Ternary Logic Gate Networks A Contractive Feedback Semantics for Reinforcement Learning A Large-Scale Dataset and Benchmark: Do Protein-Ligand Models Learn Binding Sites or Just Binding Likelihood? The Normalized Maximum Likelihood for Regular Non-Smooth Models: Measure-Theoretic Foundations and Geometric Sampling Riemannian Archetypal Analysis: Interpretable non-linear data analysis on deformed star distributions Signs Beat Floats: Low-Rank Double-Binary Adaptation for On-Device Fine-Tuning Refined Analysis of Entropy-Regularized Actor-Critic Characterizing the Representational Capacity of Neural Processes Learning Laplacian Eigenspace with Mass-Aware Neural Operators on Point Clouds From One-Pass SGD to Data Reuse: Mini-Batch Scaling Laws in Sketched Linear Regression PromptAudit: Auditing Prompt Sensitivity in LLM-Based Vulnerability Detection Fourier Feature Pyramids for Physics-Informed Neural Networks Iterative Refinement Neural Operators are Learned Fixed-Point Solvers: A Principled Approach to Spectral Bias Mitigation Complement Submodular Information Measures for Balanced and Robust Data Selection Feature Lottery? A Bifurcation Theory of Concept Emergence A computational phase transition for learning-to-sample from Ising models Structure-Aware RAG: Structured Retrieval Augmented Generation from Noisy Data for Conversational Agents Hidden-State Privacy Has an Empty Middle Momentum Streams for Optimizer-Inspired Transformers Feature Learning in Wide Neural Networks under $μ$P: Identifiability and Sparse-Dictionary Decomposition of the Mean-Field Limit Rethinking Federated Unlearning via the Lens of Memorization PILOT: Policy-Informed Learned Optimization for Adaptive Deep Network Training ECHO: Terminal Agents Learn World Models for Free Omissive Bias in Religious Representation: Benchmarking LLM Answers to Everyday Ethical Decision-making Knowledge Graph Modulated Deep Learning for Limited-Sample Clinical Data Analysis
Steering Beyond the Support: Adversarial Training on Unsupervised Jailbroken Activation Simulation
Luoyu Chen, · 2026-05-26 · via cs.LG updates on arXiv.org

View PDF HTML (experimental)

Abstract:Jailbreak prompts can trigger harmful completions on aligned LLMs, In accordance, safety steering has been proposed: test-time activation interventions that steer jailbreak activations to trigger refusal while preserving benign utility. However, existing steering methods are fundamentally supervised and tied to a static, limited training set, whereas real jailbreaks evolve and are often out-of-distributed from the training set, leading to failures on unseen attacks. In this paper, we tackle the failure on unseen jailbreaks problem, base on unsupervised latent direction discovery. We propose a bi-level adversarial training framework for zero-shot jailbreak defense. In the inner step, we simulate diverse jail-broken activations by extrapolating from refusal-state harmful-request activations via unsupervised latent direction discovery, which expands the coverage of real jailbreak activation subspaces. In the outer step, we train a potential-induced steering field to push these adversarial jailbroken states into refusal regions while keeping benign unchanged. Across three LLMs and six classical jailbreak families, our method achieves strong defense with attack success rates mostly below 5%, and rising subspace coverage throughout training helps explain the improved generalization.
Comments: accepted by ICML 2026
Subjects: Cryptography and Security (cs.CR); Machine Learning (cs.LG)
Cite as: arXiv:2605.24535 [cs.CR]
  (or arXiv:2605.24535v1 [cs.CR] for this version)
  https://doi.org/10.48550/arXiv.2605.24535

arXiv-issued DOI via DataCite (pending registration)

Submission history

From: Luoyu Chen [view email]
[v1] Sat, 23 May 2026 12:07:38 UTC (11,626 KB)