Skip to content
Sprint projectJun 22, 2026Delhi, India

Probing Jailbreak Brittleness: Capability Limits vs Alignment Failures in Small Language Models

Baisayan Bhattacharya, Sankeerthana Satini, Harshprabha, Devansh Gupta · Team Epoch

Submitted to Global South AI Safety Hackathon. Sprint projects are early-stage work by participants, not Apart Research publications.

Read the report

Report: Probing Jailbreak Brittleness: Capability Limits vs Alignment Failures in Small Language Models

Code (opens in new tab)
Share

This project investigates whether smaller language models are more susceptible to jailbreak attacks than larger models, and whether this vulnerability is due to capability limitations or alignment brittleness. We evaluate instruction-tuned Mistral and Qwen models across XSTest and a modified version of AdvBench. For each prompt, we extract final-token hidden activations from all model layers during inference and train layer-wise linear probes to test whether safe and unsafe prompts are internally separable before generation. We then compare the best probe’s internal risk prediction with the model’s generated response behaviour. This allows us to distinguish missed internal risk, where unsafe compliance occurs without probe-detected risk, from known-risk unsafe responses, where risk is internally decodable but the model still complies. Our results show that unsafe prompt information is often linearly decodable before generation, and that many unsafe compliance cases occur despite probe-detected risk. While scaling improves safety within the Mistral family, the model family also plays a major role, with Qwen models demonstrating stronger refusal behaviour. Overall, our findings suggest that jailbreak susceptibility is often better explained by brittle translation from internal risk representations to output behaviour than by absent risk detection alone.

Reviews

Judging this Sprint?

Review this project

Your public critique appears on this page without your name. Your private critique is not published; only the Apart team reads it. If you agree below, we share your review with grantmaking.ai (opens in new tab) and the Transformative AI Fund so strong projects can be funded.

Not shown on this page.

Shown on this page, without your name.

Only the Apart team reads this, and funders if you agree below.

Share my name publicly on grantmaking.ai *
Share my private critique with funders *

How much would this matter for AI safety if it worked? How innovative is it? For scores of 4-5: is this actually new to the field, or replicating recent work?

Scoring guide
  1. 1Negligible. No clear problem addressed, or no meaningful novelty.
  2. 2Limited. Addresses a real problem but with a generic or well-trodden approach. Incremental at best.
  3. 3Moderate. Clear problem with a reasonable approach; some novelty in framing or method beyond routine application of existing tools.
  4. 4Significant. Important problem with an original approach, or identifies a neglected problem area. A valuable contribution others could build on.
  5. 5Exceptional. Tackles a critical AI safety problem with a genuinely novel approach, or opens a new research direction. Clear theory of change. You'd be excited to share this with researchers in the area.

How sound are methodology, implementation, and findings?

Scoring guide
  1. 1Seriously flawed. Methodology broken, results uninterpretable, or implementation doesn't work.
  2. 2Weak. Approach has significant gaps: missing validation, flawed experimental design, or incomplete implementation.
  3. 3Competent. Technically solid given the short duration. Methodology makes sense, results are interpretable, limitations acknowledged, work builds toward clear conclusions.
  4. 4Strong. Thorough methodology with convincing validation. Results clearly support conclusions. Immediately useful for future work.
  5. 5Exceptional. Ambitious scope executed rigorously. Surprising findings, novel methods, or unusually robust validation.

How clearly are work, findings, and impact potential communicated?

Scoring guide
  1. 1Incomprehensible. Cannot determine what the project is actually claiming or doing.
  2. 2Hard to follow. Key information buried, missing, or diluted by excessive length. Significant effort to extract main points.
  3. 3Clear enough. Can understand the problem, approach, and results without undue effort. Core content clearly present: problem, method, findings, limitations.
  4. 4Well presented. Easy to follow, well-structured, appropriate level of detail. Target audience would get it quickly.
  5. 5Exceptionally clear. A pleasure to read. Complex ideas made accessible. Could serve as a model for how to present this type of work.

  1. This paper makes a clean and important conceptual distinction that the field needs more of: jailbreak vulnerability can come from (a) the model not internally recognizing a prompt as unsafe, or (b) the model recognizing risk but failing to translate that into safe behavior. The finding that most Mistral-7B unsafe compliance falls into category (b) — the probe detects risk in 11 of 12 unsafe cases — has direct implications for where safety interventions should focus. The Qwen vs. Mistral comparison demonstrates that model family and alignment tuning matter more than parameter count alone, which is an important corrective to "just scale the model" thinking.

    Suggestions for strengthening: (1) The rule-based refusal detector (checking for "I can't help", "I cannot provide", etc.) is the weakest methodological link — partial refusals and ambiguous responses may be miscategorized. Even a small human annotation pass on the uncertain cases would sharpen the compliance/refusal labels. (2) The "alignment brittleness score" combines probe confidence with known-risk rate, but the formula uses a simple product — a sensitivity analysis showing the ranking is stable under alternative formulations would be useful. (3) The Modified AdvBench synthetic-safe-prompt generation via LLM is a potential confound — LLM-generated safe prompts may not cover the same difficulty distribution as human-written safe prompts. It would be worth checking whether the XSTest results (which use original human-written safe prompts) paint the same picture, and they do seem to.

    This is solid mechanistic interpretability work with clear safety relevance. The future work direction (causal interventions via activation patching) is exactly the right next step.

    Read full reviewShow less
  2. Good job. One area of improvement would be to evaluate the probe on a different dataset than just a held-out split of the dataset used for training.

    Also, consider increasing n: as it is low right now, the per-cell comparisons are based on a low number of responses and differences may be within sample noise.

  3. I suggest the synthetic generation of safe prompts would need more rigorous evaluation to form a strong signal because the modified AdvBench needs validation.

    This work is a further piece of evidence that we need white box methods and alignment brittleness will not just be solved with scale.

    I would be interested to see causal work that tests if the decoded direction actually matters for downstream refusal behaviour.

Cite this project

@misc{bhattacharya2026probing,
  title = {{Probing Jailbreak Brittleness: Capability Limits vs Alignment Failures in Small Language Models}},
  author = {Baisayan Bhattacharya and Sankeerthana Satini and Harshprabha and Devansh Gupta},
  year = {2026},
  month = jun,
  note = {Submitted to Global South AI Safety Hackathon, an Apart Research Sprint},
  howpublished = {\url{https://apartresearch.com/sprints/projects/probing-jailbreak-brittleness-capability-limits-vs-alignment-failures-in-small-language-models-7lk9}},
  url = {https://apartresearch.com/sprints/projects/probing-jailbreak-brittleness-capability-limits-vs-alignment-failures-in-small-language-models-7lk9}
}

Build something like this at the next Sprint

AI Collusion Research Sprint · Oct 23 - 25, 2026