Safety
Revocable Learned State via Process Sidecars
arXiv:2606.30788v1 Announce Type: cross Abstract: Language models are often adapted in stages: a public skill phase, a private memory phase, and a later safety phase that learns to refuse outputs tied
arXiv:2606.30788v1 Announce Type: cross Abstract: Language models are often adapted in stages: a public skill phase, a private memory phase, and a later safety phase that learns to refuse outputs tied to the remembered entities. Revoking the memory after the safety phase is not the same problem as subtracting the memory update: the later safety optimizer has transported the memory direction. We introduce process sidecars, a two-coefficient edit family hat{heta}(lambda,gamma)=heta_{AMS}-lambdaDelta_{M}-gammahat{R}{SleftarrowM}, with hat{R}{SleftarrowM}=hat{J}{S,arepsilon}(Delta{M})-Delta_{M}, where hat{J}{S,arepsilon} is a centered secant through the realized future AdamW safety-training process. The implementation uses arepsilon=1 at the natural memory-edit scale; it reuses heta{AMS} as the positive endpoint and computes one additional safety trace at heta_{A}-Delta_{M}. We prove two things. First, the exact sidecar, using the true transported direction R_{SleftarrowM} rather than the secant estimate, at (lambda,gamma)=(1,1) recovers the counterfactual safety-only oracle heta_{AS} up to second order; the proof treats AdamW as an augmented-state map over parameters, first moments, and second moments. Second, this process information is necessary: whenever future safety training bends the memory direction, every scalar task-arithmetic edit leaves first-order counterfactual error, while the process-sidecar edit is second-order accurate. Across three models, the validation-selected 2D edit improves held-out refusal closure over naive task arithmetic in all trials, and over the gamma=lambda process-JVP subfamily, the diagonal slice of the cached 2D grid, in all paired trials.
Source: arXiv cs.CL | 2026-07-01