arXiv AI

Why Jailbreaks Succeed in Diffusion Language Models: An Energy Landscape Analysis

The paper proposes a framework that explains why jailbreak attacks succeed against diffusion-based large language models (dLLMs) by viewing safety alignment as shaping a denoising energy landscape. It identifies two attack strategies—obscuring the query’s safety disposition at initialization or forcing the denoising path across an energy barrier mid‑trajectory—and introduces three training‑free detection signals that monitor initial safety disposition and kinetic energy in complementary subspaces. Experiments on several dense and sparse dLLMs show that these signals complement each other, and any attack that evades detection also fails to produce harmful content.

arXiv AI
Sep 2

Beyond Token Positions: Safety Alignment Across Denoising Steps in Diffusion Language Models

This paper investigates safety alignment in diffusion large language models (dLLMs), which generate text via iterative denoising instead of left‑to‑right decoding. By tracking token distributions and commitment decisions across denoising steps, the authors find that refusal signals are concentrated early in the denoising process and at leading response positions, and that early committed tokens strongly influence the final safety outcome. They introduce Refusal‑Aware Early Commitment (RAEC), a training‑free decoding method that preserves early refusal signals, and demonstrate that RAEC reduces attack success rates on LLaDA and Dream while largely maintaining utility.

By Guoli Wang, Haonan Shi, Tu Ouyang, An Wang
arXiv AI
Jun 4

MaskForge: Structure-Aware Adaptive Attacks for Jailbreaking Diffusion Large Language Models

arXiv:2606. 04027v1 Announce Type: cross Abstract: Diffusion large language models (dLLMs) generate text by iteratively denoising partially masked sequences under bidirectional context, exposing a safety surface distinct from autoregressive LLMs.

By Yingzi Ma, Zhengyue Zhao, Xiaogeng Liu, Minhui Xue, Yue Zhao, Chaowei Xiao
arXiv AI
Jun 8

Step-Wise Refusal Dynamics in Autoregressive and Diffusion Language Models

arXiv:2602. 02600v3 Announce Type: replace-cross Abstract: Diffusion language models (DLMs) have recently emerged as a competitive alternative to autoregressive (AR) models, offering parallel decoding, competitive generation quality, and initial evidence of improved jailbreak robustness.

By Eliron Rahimi, Elad Hirshel, Rom Himelstein, Amit LeVi, Avi Mendelson, Chaim Baskin
arXiv Machine Learning
Jun 3

Backdooring Masked Diffusion Language Models

arXiv:2605. 19262v2 Announce Type: replace Abstract: Masked diffusion language models (MDLMs) are emerging as a compelling new paradigm for text generation, but their training-time security remains largely unexplored.

By Daniel Yiming Cao, Chengzhong Wang, Sheng-Yen Chou, Chengyu Huang, Pin-Yu Chen, Shengwei An
arXiv Machine Learning
1d ago

Refusal Localizes, the Damage Relocates: Safety Layers Under Few-Sample Fine-Tuning

The paper investigates how fine‑tuning large language models with a small number of harmful examples can erode their refusal behavior, and explores whether localizing safety‑related behavior to specific layers or directions can provide robust defenses. Experiments across six checkpoints from four model families show that harmful and benign prompts remain linearly separable after attack, and that patching clean hidden states or freezing layers up to a transition depth can restore refusal. However, attackers can bypass these defenses by spreading updates or targeting singular directions, indicating that adaptive fine‑tuning can defeat localized repairs and highlighting the need for multiple defensive checks.

By Jungseob Lee, Dongyub Jude Lee, Sugyeong Eo, Seongtae Hong, Seungyoon Lee, Heuiseok Lim
arXiv AI
Jul 9

NonTextual Target Attack

arXiv:2510. 02999v5 Announce Type: replace-cross Abstract: Existing gradient-based jailbreak attacks on Large Language Models (LLMs) typically optimize adversarial suffixes to align the LLM output with predefined target responses.

By Xinzhe Huang, Wenjing Hu, Tianhang Zheng, Kedong Xiu, Hongsheng Hu, Xiaojun Jia, Di Wang, Zhan Qin, Kui Ren