arXiv · 2602.17696
Can LLM Safety Be Ensured by Constraining Parameter Regions?
Abstract
Large language models (LLMs) are often assumed to contain ``safety regions'' -- parameter subsets whose modification directly influences safety behaviors. We conduct a systematic evaluation of four safety region identification methods spanning different parameter granularities, from individual weights to entire Transformer layers, across four families of backbone LLMs with varying sizes. Using ten safety identification datasets, we find that the identified safety regions exhibit only low to moderate overlap, as measured by IoU. The overlap drops significantly when the safety regions are further refined using utility datasets (\ie non-harmful queries). These results suggest that current techniques fail to reliably identify a stable, dataset-agnostic safety region.
Explore related subjects
Keep this discovery
Zongmin Li, Jian Su, Farah Benamara, Aixin Sun. 2026-02-06. Can LLM Safety Be Ensured by Constraining Parameter Regions?. https://arxiv.org/abs/2602.17696
Cite the original work for its findings. Save a collection to share your selection of sources.