When Are Sparse Feature Interventions Actually Localized? Matched Evaluation for SAE-Based Safety Control
Daming Luo
cs.AI, cs.CR
Submitted: 2026-07-11
Comments: 11 pages, 5 figures, 4 tables. Preliminary version; extended multi-model study in progress
License: http://arxiv.org/licenses/nonexclusive-distrib/1.0/
Terminology
Sources
- Refusal in Language Models Is Mediated by a Single Direction
- Training Verifiers to Solve Math Word Problems
- Sparse Autoencoders Find Highly Interpretable Features in Language Models
- The Llama 3 Herd of Models
- Llama Guard 3-1B-INT4: Compact and Efficient Safeguard for Human-AI Conversations
- Gemma 2: Improving Open Language Models at a Practical Size
- Llama Scope: Extracting Millions of Features from Llama-3.1-8B with Sparse Autoencoders
- Measuring Massive Multitask Language Understanding
- WildTeaming at Scale: From In-the-Wild Jailbreaks to (Adversarially) Safer Language Models
- Gemma Scope: Open Sparse Autoencoders Everywhere All At Once on Gemma 2
- HarmBench: A Standardized Evaluation Framework for Automated Red Teaming and Robust Refusal
- XSTest: A Test Suite for Identifying Exaggerated Safety Behaviours in Large Language Models
- Steering Language Models With Activation Engineering
- Representation Engineering: A Top-Down Approach to AI Transparency
Related papers
- MAVEN-T: Reinforced Heterogeneous Distillation for Real-Time Multi-Agent Trajectory Prediction
- Model Discovery Agent: LLM-assisted Bayesian experiment design for data-efficient discovery of mechanistic world models
- The Clinician's Veto: Navigating Trust, Liability, and Uncertainty in Autonomous AI Prescribing
- MindHelper: Closed-Loop Embodied Mental-State Reasoning for Precision Intervention
- Incumbent Advantage: Brand Bias and Cognitive Manipulation Dynamics in LLM Recommendation Systems
- VSAL: A Vision Solver with Adaptive Layouts for Graph Property Detection