[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-84015-en":3,"doc-seo-84015-105":30,"detail-sidebar-cat-0-en-105":83},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":20,"is_deleted":4,"is_public":21,"is_downloadable":21,"audit_status":21,"page_count":22,"language":23,"language_code":24,"site_id":25,"html_lang":24,"table_of_contents":26,"faqs":27,"seo_title":13,"seo_description":14,"update_tm":28,"read_time":29},84015,7971461740909,"Levi","https://ap-avatar.wpscdn.com/davatar_155a257f0dc6eb9ab79c44ca47cae57d",8,"Research & Report","Beyond Refusal A Same-Lineage Study of Aligned and Abliterated LLMs for Vulnerability Analysis","Large language model (LLM)-assisted software security lies on a difficult boundary: vocabulary for legitimate vulnerability analysis can resemble misuse-oriented requests. Existing safety and cybersecurity evaluations are hard to interpret because they often compare unrelated model families, mixing safety effects with architectural, training, and deployment differences. This study isolates safety state—whether refusal behavior remains ALIGNED or becomes ABLITERATED—within same-lineage models. Aligned and refusal-ablated descendants from Gemma and Qwen are evaluated across detection, CWE attribution, localization, root-cause, and executable patch validation, using controlled prompt framing.","Beyond Refusal: A Same-Lineage Study of Aligned and Abliterated LLMs for Vulnerability Analysis  \nMingchen Li∗ , Meikang Qiu†, Zifan Peng‡, Heng Fan∗ , Song Fu∗ , Junhua Ding∗ , and Yunhe Feng∗  \n∗ University of North Texas, USA  \n[MingchenLi@my.unt.edu](MingchenLi@my.unt.edu), {Heng.Fan, Song.Fu, Junhua.Ding, [Yunhe.Feng](Yunhe.Feng}@unt.edu)[}](Yunhe.Feng}@unt.edu)[@unt.edu](Yunhe.Feng}@unt.edu)  \n†Augusta University, USA  \n[qiumeikang@yahoo.com](qiumeikang@yahoo.com)  \n‡Newcastle University, United Kingdom  \n[z.peng12@newcastle.ac.uk](z.peng12@newcastle.ac.uk)  \narXiv :2607 .05842v 1 [ cs . SE] 7 Jul 2026  \nAbstract—Large language model (LLM)-assisted software security operates at a difficult boundary: the vulnerability-analysis terminology needed for legitimate code review, triage, and repair can closely resemble terminology associated with misuse. Existing safety and cybersecurity evaluations are difficult to interpret in this setting because they often compare unrelated model families, thereby conflating safety behavior with differences in architecture, scale, training data, and deployment. To isolate this factor, we study safety state: whether refusal behavior remains intact (ALIGNED) or has been refusal-ablated (ABLITERATED) within same-lineage models. We ask how this safety state affects defensive utility across software-security workflows. We compare aligned instruction-tuned models with publicly released refusalablated descendants from two model families, Gemma and Qwen. We evaluate ALIGNED and ABLITERATED states on vulnerability detection, CWE attribution, vulnerable-line localization, rootcause localization, and executable patch validation. We further treat prompt wording as a controlled framing dimension: prompts begin with neutral code-review language, add authorization context, and vary the density of cybersecurity terminology. In a Gemma-based Java/Vul4J repair-validation study, ABLITERATED achieves higher early-stage validation rates, with 67.8%, 65.0%, and 32.8% of patches judged usable, successfully applied, and successfully compiled, respectively, compared with 29.9%, 24.9%, and 9.0% for ALIGNED. In the Qwen pair, ABLITERATED improves localization performance, increasing line-level F1 from 2.08% to 3.91% and Top-1 accuracy from 4.10% to 6.95% . Overall, our results show that safety-state effects manifest not only as changes in whether models answer, but also as changes in answer coverage, localization quality, prompt sensitivity, and staged repair-validation outcomes. These findings suggest that evaluations ofLLM-based security assistants should jointly measure whether models respond, whether their usable responses are correct, and whether their outputs remain actionable across the engineering workflow.  \nIndex Terms—Large Language Models, Software Security, Vulnerability Analysis, Coding Assistant Analysis  \nI. INTRODUCTION  \nLarge language models (LLMs) are increasingly used as code-generation systems [1]–[3], programming assistants [4]–[6], and repository-level software engineering agents [7], [8] . This transition has especially important implications for software security, where LLMs are evaluated for cyber-risk assessment [9], [10], threat intelligence [11], penetration-testing assistance [12], vulnerability detection [13], and automated vulnerability repair [14],[15] . Yet software-security workflows  \nexpose a persistent boundary problem: the concepts, vocabulary, and reasoning patterns that defenders need to identify and repair vulnerabilities can closely resemble misuse-oriented requests. Recent deployment incidents make this tension concrete. For example, the June 2026 Claude Fable 5 episode highlighted how stronger safeguards around high-risk domains can also produce broad refusals for benign cybersecurity work, including reading security materials and writing defensive code [16]–[19] . For software engineering, the key question is therefore not only whether cyber-capable LLMs block harmful req","cbCaihpsfetcwlqw","https://ap.wps.com/l/cbCaihpsfetcwlqw","pdf",2292599,3,1,12,"English","en",105,"# Introduction\n## Safety-state and evaluation gap\n## Availability, correctness, and actionability","[{\"question\":\"Which evaluation tasks are used to measure defensive utility?\",\"answer\":\"The study evaluates vulnerability detection, CWE attribution, vulnerable-line localization, root-cause localization, and executable patch validation, and also varies prompt wording as a controlled framing factor.\"}]",1784192029,30,{"code":4,"msg":31,"data":32},"ok",{"site_id":25,"language":24,"slug":33,"title":13,"keywords":34,"description":14,"schema_data":35,"social_meta":78,"head_meta":80,"extra_data":82,"updated_unix":28},"beyond-refusal-a-same-lineage-study-of-aligned-and-abliterated-llms-for-vulnerability-analysis","",{"@graph":36,"@context":77},[37,53,68],{"@type":38,"itemListElement":39},"BreadcrumbList",[40,44,48,50],{"item":41,"name":42,"@type":43,"position":21},"https://docshare.wps.com","Home","ListItem",{"item":45,"name":46,"@type":43,"position":47},"https://docshare.wps.com/document/","Document",2,{"item":49,"name":12,"@type":43,"position":20},"https://docshare.wps.com/document/research-report/",{"item":51,"name":13,"@type":43,"position":52},"https://docshare.wps.com/document/beyond-refusal-a-same-lineage-study-of-aligned-and-abliterated-llms-for-vulnerability-analysis/84015/",4,{"url":51,"name":13,"@type":54,"author":55,"headline":13,"publisher":57,"fileFormat":60,"inLanguage":24,"description":14,"dateModified":61,"datePublished":62,"encodingFormat":60,"isAccessibleForFree":63,"interactionStatistic":64},"DigitalDocument",{"name":9,"@type":56},"Person",{"url":41,"name":58,"@type":59},"DocShare","Organization","application/pdf","2026-07-27","2026-07-16",true,{"@type":65,"interactionType":66,"userInteractionCount":20},"InteractionCounter",{"@type":67},"ViewAction",{"@type":69,"mainEntity":70},"FAQPage",[71],{"name":72,"@type":73,"acceptedAnswer":74},"Which evaluation tasks are used to measure defensive utility?","Question",{"text":75,"@type":76},"The study evaluates vulnerability detection, CWE attribution, vulnerable-line localization, root-cause localization, and executable patch validation, and also varies prompt wording as a controlled framing factor.","Answer","https://schema.org",{"og:url":51,"og:type":79,"og:title":13,"og:site_name":58,"og:description":14},"article",{"robots":81,"canonical":51},"index,follow",{"doc_id":7,"site_id":25},{"code":4,"msg":5,"data":84},[85,89,93,97,102,107,112,114,119,122,126],{"id":21,"doc_module":4,"doc_module_name":46,"category_name":86,"show_sort_weight":87,"slug":88},"Story & Novel",90,"story-novel",{"id":47,"doc_module":4,"doc_module_name":46,"category_name":90,"show_sort_weight":91,"slug":92},"Literature",80,"literature",{"id":52,"doc_module":4,"doc_module_name":46,"category_name":94,"show_sort_weight":95,"slug":96},"Exam",70,"exam",{"id":98,"doc_module":4,"doc_module_name":46,"category_name":99,"show_sort_weight":100,"slug":101},5,"Comic",60,"comic",{"id":103,"doc_module":4,"doc_module_name":46,"category_name":104,"show_sort_weight":105,"slug":106},6,"Technology",50,"technology",{"id":108,"doc_module":4,"doc_module_name":46,"category_name":109,"show_sort_weight":110,"slug":111},7,"Healthcare",40,"healthcare",{"id":11,"doc_module":4,"doc_module_name":46,"category_name":12,"show_sort_weight":29,"slug":113},"research-report",{"id":115,"doc_module":4,"doc_module_name":46,"category_name":116,"show_sort_weight":117,"slug":118},9,"Religion & Spirituality",20,"religion-spirituality",{"id":117,"doc_module":4,"doc_module_name":46,"category_name":120,"show_sort_weight":117,"slug":121},"World Cup","world-cup",{"id":123,"doc_module":4,"doc_module_name":46,"category_name":124,"show_sort_weight":123,"slug":125},10,"Lifestyle","lifestyle",{"id":127,"doc_module":4,"doc_module_name":46,"category_name":128,"show_sort_weight":98,"slug":129},19,"General","general"]