SearcharxivSearch

arXiv subjects

Saraga Sakthidharan

Publications and source records attributed to Saraga Sakthidharan.

2 recordsLinked to original sources

You Snooze, You Lose: Automatic Safety Alignment Restoration through Neural Weight Translation

Public repositories now distribute thousands of specialized Low-Rank Adaptation (LoRA) modules, but a third-party adapter routinely arrives without the refusal behavior the same adapter would have had if it had been trained responsibly. Restoring it by fine-tuning on safety data induces the opposite failure: the domain expertise the adapter was published to provide degrades. A practitioner who downloads a finished adapter holds neither the domain corpus nor a safety corpus, so neither remedy is available. We propose Neural Weight Translation (NeWTral), which maps unsafe domain adapters to their safety-aligned counterparts entirely within parameter space while preserving their expertise. NeWTral is a non-linear translator pre-trained on unsafe-to-safe adapter pairs, with a Mixture of Experts router that blends a high-fidelity surgical translator and an aggressive alignment expert per tensor. Across four architectural families (Llama, Mistral, Qwen, Gemma) at scales up to 72B parameters and eight professional domains, NeWTral cuts the average Attack Success Rate from 70% to 13% while retaining 88% knowledge fidelity. The effect reproduces on JailbreakBench, on 12 of 14 adapters downloaded from a public model hub, and under automated jailbreak attacks. Curing is a single pass over the weights, needing no original training data and no retraining.

cs.CR

Security in LLM-as-a-Judge: A Comprehensive SoK

LLM-as-a-Judge (LaaJ) is a novel paradigm in which powerful language models are used to assess the quality, safety, or correctness of generated outputs. While this paradigm has significantly improved the scalability and efficiency of evaluation processes, it also introduces novel security risks and reliability concerns that remain largely unexplored. In particular, LLM-based judges can become both targets of adversarial manipulation and instruments through which attacks are conducted, potentially compromising the trustworthiness of evaluation pipelines. In this paper, we present the first Systematization of Knowledge (SoK) focusing on the security aspects of LLM-as-a-Judge systems. We perform a comprehensive literature review across major academic databases, analyzing 863 works and selecting 45 relevant studies published between 2020 and 2026. Based on this study, we propose a taxonomy that organizes recent research according to the role played by LLM-as-a-Judge in the security landscape, distinguishing between attacks targeting LaaJ systems, attacks performed through LaaJ, defenses leveraging LaaJ for security purposes, and applications where LaaJ is used as an evaluation strategy in security-related domains. We further provide a comparative analysis of existing approaches, highlighting current limitations, emerging threats, and open research challenges. Our findings reveal significant vulnerabilities in LLM-based evaluation frameworks, as well as promising directions for improving their robustness and reliability. Finally, we outline key research opportunities that can guide the development of more secure and trustworthy LLM-as-a-Judge systems.

cs.CR