This paper investigates safety alignment in diffusion large language models (dLLMs), which generate text via iterative denoising instead of left‑to‑right decoding. By tracking token distributions and commitment decisions across denoising steps, the authors find that refusal signals are concentrated early in the denoising process and at leading response positions, and that early committed tokens strongly influence the final safety outcome. They introduce Refusal‑Aware Early Commitment (RAEC), a training‑free decoding method that preserves early refusal signals, and demonstrate that RAEC reduces attack success rates on LLaDA and Dream while largely maintaining utility.
By Guoli Wang, Haonan Shi, Tu Ouyang, An Wang
arXiv:2608. 07430v1 Announce Type: cross Abstract: Diffusion Large Language Models (DLLMs) replace autoregressive next-token prediction with iterative parallel denoising, yet their internal safety mechanisms remain poorly understood.
By Elena Dumitrescu, Gert Lek, Lydia Y. Chen, J\'er\'emie Decouchant
arXiv:2508. 10029v3 Announce Type: replace-cross Abstract: Safety-aligned large language models can still be manipulated through white-box interventions that modify their internal representations.
By Wenpeng Xing, Bohan Yang, Mohan Li, Chunqiang Hu, Haitao Xu, Ningyu Zhang, Bo Lin, Meng Han
arXiv:2606. 04027v1 Announce Type: cross Abstract: Diffusion large language models (dLLMs) generate text by iteratively denoising partially masked sequences under bidirectional context, exposing a safety surface distinct from autoregressive LLMs.
By Yingzi Ma, Zhengyue Zhao, Xiaogeng Liu, Minhui Xue, Yue Zhao, Chaowei Xiao
arXiv:2606. 25182v1 Announce Type: cross Abstract: Jailbreak attacks reveal a persistent weakness in aligned Large Language Models: carefully crafted prompts can elicit policy-violating responses despite safety training.
By Sofiia Nikolenko, Michele Papucci, Mina Rezaei, Shireen Kudukkil Manchingal
arXiv:2602. 02600v3 Announce Type: replace-cross Abstract: Diffusion language models (DLMs) have recently emerged as a competitive alternative to autoregressive (AR) models, offering parallel decoding, competitive generation quality, and initial evidence of improved jailbreak robustness.
By Eliron Rahimi, Elad Hirshel, Rom Himelstein, Amit LeVi, Avi Mendelson, Chaim Baskin