arXiv AI

Unpredictable Safety: Domain-Dependent Compliance and the Transparency Gap in Open-Weight LLMs

arXiv:2606. 04035v1 Announce Type: cross Abstract: We present a systematic study of domain-dependent safety behavior in open-weight LLMs: 7 standardized experiments across 7 ethical domains, testing 5 models (12B--70B) in 4,200 interactions with dual-judge validation.

arXiv AI
Sep 3

FUSE: An Evaluating Framework for Dangerous Capabilities of LLMs

The paper introduces FUSE, a modular framework that evaluates large language models (LLMs) for dangerous capabilities across three orthogonal pipelines: Knowledge (K), Defense (D), and Harm (H). Using a chemical‑biological module, the authors assess 12 commercial LLMs, revealing divergent profiles among models and families, and showing that newer models increase knowledge while only partially improving defense. The framework’s reliability is supported by high cross‑judge consistency and low inter‑pipeline correlations.

By Zhengyi Jin, Ru Zhang, Xiao Chen, Xinbo Liu, Jiaxuan Lin, Jia Huang, Jianyi Liu, Zhen Yang
arXiv AI
Sep 17

Do Frontier Models Seek Safety Evidence Before Acting?

The paper investigates whether large language models decide to gather safety-relevant evidence before acting. Using the SAFE benchmark, the authors evaluate models such as GPT‑5.5, o3, Claude Opus, and Claude Sonnet, finding distinct evidence‑acquisition strategies that vary with retrieval cost, severity, and presentation. Across models, expected‑value reasoning dominates Stage 1 rationales, and evidence framing can alter decisions near the inspection threshold while probability is often cited despite limited influence.

By Omer Tafveez
arXiv AI
Aug 19

Fool's Gold: Defensive Deception Against Safety-Removal Attacks on Open-Weight Models

The paper introduces ‘Fool’s Gold’, a defensive deception technique for open‑weight language models that hardens them against safety‑removal attacks. By training decoy responses within a differentiable simulation of the attack, the method poisons the payoff of stripped refusal mechanisms, producing confident but falsified answers to hazardous requests while preserving benign behavior. Experiments on seven models (9B‑122B) show that 51‑90% of attacked‑state responses become decoys, with the defense accounting for 27‑84% of this effect, and that the defended 122B model remains within benign‑behavior budgets.

By Mark Russinovich