Refusal Steering: Fine-grained Control over LLM Refusal Behaviour for Sensitive Topics

📅 2025-12-18
📈 Citations: 0
✨ Influential: 0
📄 PDF
🤖 AI Summary
This work addresses inference-time refusal of large language models (LLMs) on politically sensitive topics. We propose Refusal Steering—a fine-grained, tuning-free control method that steers model activations to suppress undesired refusals while preserving safety and utility. Instead of hand-crafted rules, we employ an LLM-as-a-judge paradigm for automated refusal detection. A ridge-regularized steering vector is optimized in the activation space to precisely decouple refusal-oriented from compliant behavior. We empirically find that refusal signals are highly concentrated in deep Transformer layers and exhibit high-dimensional distributed patterns. On Qwen3-Next-80B, Refusal Steering eliminates excessive refusal on politically sensitive queries without degrading performance on JailbreakBench (safety) or standard general-purpose benchmarks—maintaining near-baseline accuracy. The method generalizes across model scales (4B and 80B variants) and enables bidirectional, real-time control over refusal behavior (i.e., on/off switching).

Technology Category

Machine Learning: Large Multimodal Models (LMMs)Natural Language Processing: Safety and RobustnessComputer Vision: Large Vision Models

Application Category

Responsible Web: Social and technical mechanisms of refusal for web technologies and applicationsEconomics, Online Markets and Human Computation: LLM based quality controls for crowd workSearch and Retrieval-Augmented AI: Search Tool Learning with LLM: Teaching LLMs to invoke search and make use of retrieved information
📝 Abstract
We introduce Refusal Steering, an inference-time method to exercise fine-grained control over Large Language Models refusal behaviour on politically sensitive topics without retraining. We replace fragile pattern-based refusal detection with an LLM-as-a-judge that assigns refusal confidence scores and we propose a ridge-regularized variant to compute steering vectors that better isolate the refusal--compliance direction. On Qwen3-Next-80B-A3B-Thinking, our method removes the refusal behaviour of the model around politically sensitive topics while maintaining safety on JailbreakBench and near-baseline performance on general benchmarks. The approach generalizes across 4B and 80B models and can also induce targeted refusals when desired. We analize the steering vectors and show that refusal signals concentrate in deeper layers of the transformer and are distributed across many dimensions. Together, these results demonstrate that activation steering can remove political refusal behaviour while retaining safety alignment for harmful content, offering a practical path to controllable, transparent moderation at inference time.
Problem

Research questions and friction points this paper is trying to address.

Control LLM refusal on sensitive topics
Replace pattern detection with LLM-as-judge
Remove political refusal while keeping safety
Innovation

Methods, ideas, or system contributions that make the work stand out.

LLM-as-a-judge replaces pattern-based refusal detection
Ridge-regularized variant computes precise refusal steering vectors
Activation steering removes political refusals while keeping safety