April 2026Unreviewed
Mechanistic Steering of LLMs Reveals Layer-wise Feature Vulnerabilities in Adversarial Settings
Nilanjana Das, Manas Gaur
Abstract
Large language models (LLMs) can still be jailbroken into producing harmful outputs despite safety alignment. Existing attacks show this vulnerability, but not the internal mechanisms that cause it. This study asks whether jailbreak success is driven by identifiable internal features rather than prompts alone. We propose a three-stage pipeline for Gemma-2-2B using the BeaverTails dataset. First, we extract concept-aligned tokens from adversarial responses via subspace similarity. Second, we appl
Categories
Framework mappings
OWASP Top 10 for LLM Applications
- LLM01Prompt Injection
MITRE ATLAS
- AML.T0054LLM Jailbreak
Suggested from the entry's categories.
Cite
@misc{das2026mechanistic,
title = {{Mechanistic Steering of LLMs Reveals Layer-wise Feature Vulnerabilities in Adversarial Settings}},
author = {Nilanjana Das and Manas Gaur},
year = {2026},
month = apr,
eprint = {2604.23130},
archivePrefix = {arXiv},
url = {https://arxiv.org/abs/2604.23130}
}