{"_canonicalization":{"envelope_id":"axm_ + sha256(envelope minus {signature, axiom_id, anchors})","envelope_signature":"ed25519(envelope minus {signature, axiom_id})","json":"sort_keys=True, separators=(',',':'), ensure_ascii=False, allow_nan=False, utf-8","leaf_hash":"sha256(0x00 || canonical_json(envelope_full))","seal_signature":"ed25519(seal minus {signature, sig_algorithm})"},"axiom_id":"axm_d0e0b060b10ab1a663a0131721e990750c17f2c0a312a642a7c033956b39eaa9","bitcoin_anchor":{"bitcoin_attestations":[],"calendar_attestations":[],"ots_url":"","stamped_at":"","status":"pending_next_stamp"},"envelope":{"anchors":[{"chain":"crovia.axiom_graph","height":0,"merkle_proof":"spider_vendor_press_v1","root_at_anchor":"spider_vendor_press_v1"}],"axiom_id":"axm_d0e0b060b10ab1a663a0131721e990750c17f2c0a312a642a7c033956b39eaa9","axiom_type":"AX.OBS","body":{"axiom_subtype":"news.vendor_press.v1","category":"news","fingerprint":"413082d4a97519a1f84d2ce01356109d8117dd83708c868815fefbd0137f1e10","published":"Fri, 03 Jul 2026 00:00:00 -0400","receipt_hash":"413082d4a97519a1f84d2ce01356109d8117dd83708c868815fefbd0137f1e10","schema":"spider.news.vendor_press.v1","spider":"vendor_press","spider_record":{"axiom_subtype":"news.vendor_press.v1","category":"news","decision_hint":"POSITIVE","envelope_target":"AX.OBS","fingerprint":"413082d4a97519a1f84d2ce01356109d8117dd83708c868815fefbd0137f1e10","observed_at":"2026-07-03T04:43:38.241623Z","parent_run_hash":"f0e30469786257a5e74170498cacb4c028623bf32d6d06d4dbadc488960545be","published":"Fri, 03 Jul 2026 00:00:00 -0400","runtime_version":"0.1.0","schema":"spider.news.vendor_press.v1","source_status":200,"source_url":"https://export.arxiv.org/rss/cs.AI","spider":"vendor_press","summary_excerpt":"arXiv:2607.01859v1 Announce Type: new \nAbstract: Safety training for large language models (LLMs) is conducted predominantly in English, leaving uncertain how well safety mechanisms generalize to low-resource languages and mixed-language code-switching. We show that this creates an epistemic gap in which models confidently generate harmful responses for inputs that fall outside the distribution of their safety training. To study this phenomenon, we introduce STEER (Safety Targeted Embedding Exploit via Refinement), a gradient-guided attack that identifies words contributing most strongly to the model's refusal behavior and iteratively translates them into low-resource languages to suppress refusal while preserving harmful intent. Across six open-source 8B-parameter models, STEER achieves attack success rates of up to 93.0% on JailbreakBench and 96.7% on AdvBench, outperforming random code-switching and Greedy Coordinate Gradient (GCG). The resulting prompts also transfer to GPT-4o-mini","title":"Safety Targeted Embedding Exploit via Refinement","url":"https://arxiv.org/abs/2607.01859","vendor":"arxiv_cs_ai"},"summary":"arXiv:2607.01859v1 Announce Type: new \nAbstract: Safety training for large language models (LLMs) is conducted predominantly in English, leaving uncertain how well safety mechanisms generalize to low-resource languages and mixed-language code-switching. We show that this creates an epistemic gap in which models confidently generate harmful responses for inputs that fall outside the distribution of their safety training. To study this phenomenon, we introduce STEER (Safety Targeted Embedding Exploit via Refinement), a gradient-guided attack that identifies words contributing most strongly to the model's refusal behavior and iteratively translates them into low-resource languages to suppress refusal while preserving harmful intent. Across six open-source 8B-parameter models, STEER achieves attack success rates of up to 93.0% on JailbreakBench and 96.7% on AdvBench, outperforming random code-switching and Greedy Coordinate Gradient (GCG). The resulting prompts also transfer to GPT-4o-mini","title":"Safety Targeted Embedding Exploit via Refinement","vendor":"arxiv_cs_ai"},"confidence":{"method":"deterministic"},"decision":"POSITIVE","issued_at":"2026-07-03T04:43:38Z","notes":"Spider vendor_press (news) news.vendor_press.v1","object":{"captured_by":"crovia.spider.vendor_press","primary_source_url":"https://arxiv.org/abs/2607.01859"},"predecessors":[],"schema":"crovia.axiom.v1","signature":"ed25519:b081421d0460f875c05b2165d226f732e605c3e9fc8ed1c35028b4b096382a653a7e2eb46804e95243a7a251c70e9e9db326778cd8bf8658d17df16c1c22aa01","signer":"crovia.substrate","subject":{"observed_at":"2026-07-03T04:43:38Z","source_collector":"spider:vendor_press","target_id":"https://arxiv.org/abs/2607.01859"},"tsa":{"authority":"crovia.substrate.bootstrap","rfc3161_token":"{\"kind\":\"crovia.bootstrap.tsa\",\"source_jsonl\":\"/opt/crovia/spider/data/news/vendor_press_v1.jsonl\",\"source_seal_merkle_root\":\"spider_vendor_press_v1\",\"upgrade_path\":\"Sessione H \\u2014 OpenTimestamps weekly anchor\"}"},"zk_mode":"clear","zk_proof":null},"ledger":{"leaf_hash":"5795efad9881d07d123b8978a38dc17d2692b5c579a55c27addf570a5b5a5dcb","leaf_index":275378,"ledger_path":"/opt/crovia/substrate/axiom_ledger.jsonl"},"merkle_proof":{"hash_alg":"sha256","leaf_prefix":"0x00","node_prefix":"0x01","odd_leaf_rule":"duplicate_last","path":[{"sibling":"f9dca8c7a90cbcb9670edf495f8b9ad94c26517be01c85e2cfa7c596b4e5f31a","side":"right"},{"sibling":"efc67deee8df1ac6acd8ee3d6c85a3a5956167c9755d946ef9f7374cb52d24a2","side":"left"},{"sibling":"3f7f7b2a7901bdd6c05753577e26fd05d53e44d06e1d398cafa010a5c5230b21","side":"right"},{"sibling":"a2a95160df10f9d884526b4b9b7cac62229050ebfac3f73b45fcbdf75cc44c6d","side":"right"},{"sibling":"302abcf77914ae64e183bee5d749db54ba5702c21b44465e6452e3b0c63d2db8","side":"left"},{"sibling":"1031e5965521cd2d57d0a685e70068eda5d4e9645dbb1aca1d0133d801ecf1e2","side":"left"},{"sibling":"90e9fb2a20374342836f11695e291756a1f8a0197a80f5da7958594a976dd668","side":"right"},{"sibling":"fd055e725b36f5bebbaeb18583f9d7011c4d8c2a608a11cbd2c166cd895e7a85","side":"left"},{"sibling":"e1a65581e9d68211aa8ba0d138c8d2a4e80afd551e6d1b00c4575c39085df705","side":"left"},{"sibling":"92c062f377cd53076b8dfe55c25ab217059e20113433673cc5747b9348b07e01","side":"left"},{"sibling":"e36f7633c67452f41a7377a7bec9b2d454442688d26539321eebf92cae9db0f0","side":"right"},{"sibling":"4dbd8247ba08a5432c7d6540711da9acb2f59e6189865aa8552dee37f69286a9","side":"right"},{"sibling":"41cd1885dc3fcb51e49eeb887d6d22ec2cfa58df0e4f8d7c7dddf3a1b0ce8249","side":"left"},{"sibling":"8a09562f6b247c1c3cd1fea36cb3b8f1cf5c575479dd514573856a380a964bf5","side":"left"},{"sibling":"723981908169653ca6d835aa9b8381a8c7ad3e3e3830d0792bc32032cda615ee","side":"right"},{"sibling":"c0594fa1ee81d5f019cccc7b5e51af603c6d7e43995498c451012060c7d06165","side":"right"},{"sibling":"4de6a2fb22efbb50c84dc62abeb0f2cbc8c663a9540aeba9e758ebfdfe3e86dd","side":"right"},{"sibling":"fdbb3519f8dc411a4043dfb5abdbfea5441e130326183ac2247c42584033f152","side":"right"},{"sibling":"1cecb7f447febd025aac272837c80de218aecc6485d2395a509b2a1f1b9c746e","side":"left"}]},"schema":"crovia.axiom_proof.v1","seal":{"first_collector_run_id":"","first_receipt_hash":"","jsonl_path":"/opt/crovia/substrate/axiom_ledger.jsonl","key_id":"430895f101d38164","last_collector_run_id":"","last_receipt_hash":"","leaf_count":275799,"merkle_root":"2581d0d6e5fa345cdf2e8ab3b191ace76d6b14189901ab0e4c2291ca1d1ae1e6","public_key_hex":"cf742e26f75669dc673cb5c0786a1ae23ae8ca19c347317192ce40c28a7ff25c","run_id":"hourly_json_retrofit_20260703T053701Z","schema":"crovia.seal.v1","seal_family_version":"crovia-seal-family/1","seal_kind":"substrate_batch","sealed_at":"2026-07-03T05:38:09Z","sig_algorithm":"ed25519","signature":"e44a386a5ae00c0e7fc67b1179bb9060bf0fefc006e454fec70e27668182ff497d1e2faf0c3b22de0917beefb7c80e880dae925a3f67e1b16aa0eb44bf947407","signer_version":"1.1.0"},"trust_root":{"key_id":"430895f101d38164","public_key_hex":"cf742e26f75669dc673cb5c0786a1ae23ae8ca19c347317192ce40c28a7ff25c","signature_algorithm":"ed25519","url":"/registry/canon/TRUST_ROOT.md"},"verifier":{"spec":"/registry/canon/AXIOM_RECEIPT_v1.md","url":"/v/axm_d0e0b060b10ab1a663a0131721e990750c17f2c0a312a642a7c033956b39eaa9"}}