Dynamic Adversarial Fine-Tuning Reorganizes Refusal Geometry
arXiv:2604.27019v1 Announce Type: cross Abstract: Safety-aligned language models must refuse harmful requests without collapsing into broad over-refusal, but the training-time mechanisms behind this t