ChatPaper.aiChatPaper

C-ΔΘ:面向选择性拒答的电路约束权重演算法

C-ΔΘ: Circuit-Restricted Weight Arithmetic for Selective Refusal

February 4, 2026
作者: Aditya Kasliwal, Pratinav Seth, Vinay Kumar Sankarapu
cs.AI

摘要

现代部署要求大语言模型大规模实施安全策略,但现有控制方案多依赖推理时干预,这会增加持续的计算成本与服务复杂度。激活导向技术虽被广泛采用,但需要运行时钩子且成本随生成次数线性增长;条件导向变体通过门控机制提升选择性,却仍保留推理时控制路径。我们提出核心问题:能否将选择性拒绝完全移至离线阶段?即能否将对特定类别拒绝机制的机理理解,蒸馏为可部署为标准检查点的电路约束权重更新?我们提出C-Δθ:电路约束权重演算法,其(i)通过EAP-IG定位拒绝因果计算为稀疏电路,(ii)仅基于该电路(通常<5%参数)计算约束权重更新ΔθC。应用ΔθθC可生成即插即用的编辑检查点,无需推理时钩子,将成本从逐请求干预转移至一次性离线更新。我们在拒绝与效用基准测试中评估了类别靶向选择性与能力保留效果。
English
Modern deployments require LLMs to enforce safety policies at scale, yet many controls rely on inference-time interventions that add recurring compute cost and serving complexity. Activation steering is widely used, but it requires runtime hooks and scales cost with the number of generations; conditional variants improve selectivity by gating when steering is applied but still retain an inference-time control path. We ask whether selective refusal can be moved entirely offline: can a mechanistic understanding of category-specific refusal be distilled into a circuit-restricted weight update that deploys as a standard checkpoint? We propose C-Δθ: Circuit Restricted Weight Arithmetic, which (i) localizes refusal-causal computation as a sparse circuit using EAP-IG and (ii) computes a constrained weight update ΔθC supported only on that circuit (typically <5% of parameters). Applying ΔθC yields a drop-in edited checkpoint with no inference-time hooks, shifting cost from per-request intervention to a one-time offline update. We evaluate category-targeted selectivity and capability retention on refusal and utility benchmarks.
PDF11February 12, 2026