ALTSTEER: Selective Safety Steering for Moving Beyond Hard Refusals to Constructive Alternatives
cs.CL, cs.SE
Submitted: 2026-08-31
Updated: 2026-08-31
Comments: Accepted at EMNLP 2026 Main Conference
Code: https://github.com/tatsu-lab/stanford_alpaca
License: http://creativecommons.org/licenses/by/4.0/
The gist: Safety alignment is essential for deploying large language models, requiring systems to prevent harmful compliance while preserving helpfulness on benign requests.
Terminology
Abstract
Safety alignment is essential for deploying large language models, requiring systems to prevent harmful compliance while preserving helpfulness on benign requests. Activation steering offers a training-free inference-time approach to safety control, but effective safety steering requires addressing two coupled questions: when to intervene and how generation should be shaped after intervention. However, existing safety steering methods remain limited along both dimensions, as their triggering mechanisms can be unstable across domains and refusal-oriented steering often yields rigid refusals rather than constructive safe guidance. To address these limitations, we propose ALTSTEER, an inference-time framework that couples selective intervention with refusal-anchored constructive redirection within a single inference pass. ALTSTEER uses an internal refusal-relevant signal to decide when to steer, and applies staged steering to shift generation from refusal-oriented control toward constructive alternatives. Evaluations on Llama-3.1 and Qwen2.5 show that ALTSTEER preserves benign utility while improving constructive safe-completion behavior, especially on models that otherwise tend to produce short refusals for harmful requests.
Sources
- Training Verifiers to Solve Math Word Problems
- Length-Controlled AlpacaEval: A Simple Way to Debias Automatic Evaluators
- The Llama 3 Herd of Models
- Mistral 7B
- Large Language Model Safety: A Holistic Survey
- Steering Language Models With Activation Engineering
- A Comprehensive Survey in LLM(-Agent) Full Stack Safety: Data, Training and Deployment
- Qwen2.5 Technical Report
- From Hard Refusals to Safe-Completions: Toward Output-Centric Safety Training
- Uncovering Latent Chain of Thought Vectors in Language Models
- Representation Engineering: A Top-Down Approach to AI Transparency
- Universal and Transferable Adversarial Attacks on Aligned Language Models
Related papers
- Exploring Solution Divergence and Its Effect on Large Language Model Problem Solving
- Ishigaki-IDS-Bench: A Benchmark for Generating Information Delivery Specification from BIM Information Requirements
- Subliminal Steering: Stronger Encoding of Hidden Signals
- MedStruct-S: A Benchmark for Key Discovery, Key-Conditioned QA and Semi-Structured Extraction from OCR Clinical Reports
- The End of Transformers? On Challenging Attention and the Rise of Sub-Quadratic Architectures
- Untangling the Mechanisms of Misleading Context in Medical Question Answering