arXiv · 2609.36477
Guard Models Are Overconfident Where Base Models Are Uncertain
Abstract
Guard models are used as safety classifiers, with confidence scores driving downstream moderation decisions. We evaluate five guard models for prompt classification and find that although several are nearly calibrated on clean inputs, adversarial attacks degrade their calibration by an order of magnitude, turning false negatives into high-confidence errors indistinguishable from correct detections. Comparing each guard with its corresponding base LM, we find that uncertainty signals often remain available, with the base model typically expressing uncertainty on the same inputs where the guard fails. Layer-wise analyses localize this guard-base divergence to later layers, where guard models exhibit sharper safe/unsafe separation and lower-rank representations, while adversarial harmful inputs lie closer to the clean-safe region. These findings highlight a mismatch between guard confidence and base model uncertainty under attack.
Explore related subjects
Keep this discovery
Explore connections, maps & timelines
Jonghyun Hong, MinJae Jung, Minwoo Kim. 2026-09-29. Guard Models Are Overconfident Where Base Models Are Uncertain. https://arxiv.org/abs/2609.36477
Cite the original work for its findings. Save a collection to share your selection of sources.