{
  "id": 6470,
  "url": "https://arxiv.org/abs/2604.01604v2",
  "title": "CRaFT: Circuit-Guided Refusal Feature Selection via Cross-Layer Transcoders",
  "summary": "While modern LLMs are aligned to refuse harmful requests, it is essential to understand the underlying mechanistic basis of this refusal behavior for model safety analysis. For example, steering-based jailbreak attacks exploit this by identifying and manipulating sparse, neuron-like refusal features to bypass safety guardrails. Current feature selection methods primarily rely on how strongly features activate on harmful prompts. However, activation strength alone often captures superficial heuri",
  "authors": "Su-Hyeon Kim, Hyundong Jin, Yejin Lee, Yo-Sub Han",
  "category": "research",
  "topics": "safety-alignment",
  "orgs": null,
  "regions": null,
  "published_at": "2026-04-02T04:28:11.000Z",
  "fetched_at": "2026-07-14T16:32:33.098Z",
  "source_slug": "arxiv-ethics",
  "source_name": "arXiv",
  "source_homepage": "https://arxiv.org",
  "ethics_ai_record_url": "https://ethics.ai/record/6470",
  "original_url": "https://arxiv.org/abs/2604.01604v2",
  "evidence_status": "source-only",
  "attribution": "via ethics.ai"
}