cd /news/ai-safety/quad-state-safety-evaluation-of-open… · home › topics › ai-safety › article
[ARTICLE · art-147322] src=arxiv.org ↗ pub= topic=ai-safety verified=true sentiment=· neutral

Quad-State Safety Evaluation of Open-Weight Large Language Models on Non-Canonical Inputs

A new arXiv paper (2610.09033v1) introduces the Adversarial Surface-Form Robustness Dataset (ASRD), 2,100 prompts across seven surface-form families, and evaluates five open-weight language models to produce 10,500 responses under a Quad-State Evaluation Rubric. Emoji and invisible Unicode variations caused almost no comprehension failure, with pooled harmful compliance of 20.27% and 17.20% against a 22.87% baseline driven mainly by Mistral 7B, while leetspeak, encoded wrappers, and hybrid transformations scored 2.40%, 0.13%, and 2.40% with comprehension failure rising to 36.47%, 65.60%, and 34.47%. Raw output inspection revealed three response behaviors: hallucinated benignity, structural collapse, and language drift.

by read1 min views1 publishedOct 8, 2026

arXiv:2610.09033v1 Announce Type: new Abstract: Standard safety evaluations of large language models assess harmful requests written in canonical plain text, while models in real-world deployment routinely receive inputs containing emojis, altered spellings, encoded strings, and character-level variations. This work introduces the Adversarial Surface-Form Robustness Dataset (ASRD), comprising 2,100 prompts across seven distinct surface-form families. Five open-weight language models are evaluated across these prompts, producing 10,500 responses. The Quad-State Evaluation Rubric classifies each response into one of four outcomes: harmful compliance, safe response, comprehension failure, or indeterminate. Emoji and invisible Unicode variations cause almost no comprehension failure, with pooled harmful compliance of 20.27% and 17.20% against a 22.87% baseline that is driven mainly by Mistral 7B, whereas leetspeak, encoded wrappers, and hybrid transformations score 2.40%, 0.13%, and 2.40% while comprehension failure rises to 36.47%, 65.60%, and 34.47%. Inspection of raw model outputs reveals three response behaviors: hallucinated benignity, structural collapse, and language drift. Project page: www.pavanmaddula.com/quadstate

── more in #ai-safety 4 stories · sorted by recency
── more on @adversarial surface-form robustness dataset 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
→ Live at https://your-agent.zahid.host ✓
Get free account → Pricing
from €0/mo · no card required
LIVE [news/quad-state-safety-ev…] indexed:0 read:1min 2026-10-08 · —