Small Changes, Big Impact: How Manipulating a Few Neurons Can Drastically Alter LLM Aggression
Jaewook Lee, Junseo Jang, Oh-Woog Kwon, Harksoo Kim
Abstract
Recent remarkable advances in Large Language Models (LLMs) have led to innovations in various domains such as education, healthcare, and finance, while also raising serious concerns that they can be easily misused for malicious purposes. Most previous research has focused primarily on observing how jailbreak attack techniques bypass safety mechanisms like Reinforcement Learning through Human Feedback (RLHF). However, whether there are neurons within LLMs that directly govern aggression has not been sufficiently investigated. To fill this gap, this study identifies specific neurons ("aggression neurons") closely related to the expression of aggression and systematically analyzes how manipulating them affects the model's overall aggression. Specifically, using a large-scale synthetic text corpus (aggressive and non-aggressive), we measure the activation frequency of each neuron, then apply masking and activation techniques to quantitatively evaluate changes in aggression by layer and by manipulation ratio. Experimental results show that, in all models, manipulating only a small number of neurons can increase aggression by up to 33%, and the effect is even more extreme when aggression neurons are concentrated in certain layers. Moreover, even models of the same scale exhibit nonlinear changes in aggression patterns, suggesting that simple external safety measures alone may not be sufficient for complete defense.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 2fea520c-5040-420b-8cf7-82b07fa2b21dCited by top-tier papers2
- The Achilles’ Heel of LLMs: How Altering a Handful of Neurons Can Cripple Language AbilitiesZixuan Qin, Qingchen Yu, Kunlin Lyu, Zhaoxin Fan et al.ICLR 2026 · 10 citations
- Make LLMs See Like Investigators, Not Just Think More: The Role of Structured Analysis in Investigative ReasoningJaewook Lee, Myeong-Cheol Kang, Jong-hun ShinACL 2026
Builds on3
- ArtPrompt: ASCII Art-based Jailbreak Attacks against Aligned LLMsFengqing Jiang, Zhangchen Xu, Luyao Niu, Zhen Xiang et al.ACL 2024 · 36 citations
- Jailbreak Open-Sourced Large Language Models via Enforced DecodingHangfan Zhang, Zhimeng Guo, Huaisheng Zhu, Bochuan Cao et al.ACL 2024
- Language-Specific Neurons: The Key to Multilingual Capabilities in Large Language ModelsTianyi Tang, Wenyang Luo, Haoyang Huang, Dongdong Zhang et al.ACL 2024
Related papers
- Towards Understanding Safety Alignment: A Mechanistic Perspective from Safety NeuronsJianhui Chen, Xiaozhi Wang, Zijun Yao, Yushi Bai et al.NeurIPS 2025 · 53 citations
- Shaping the Safety Boundaries: Understanding and Defending Against Jailbreaks in Large Language ModelsLang Gao, Jiahui Geng, Xiangliang Zhang, Preslav Nakov et al.ACL 2025
- Safety Alignment via Constrained Knowledge UnlearningZesheng Shi, Yucheng Zhou, Jing Li, Yuxin Jin et al.ACL 2025 · 8 citations
- Understanding and Enhancing Safety Mechanisms of LLMs via Safety-Specific NeuronYiran Zhao, Wenxuan Zhang, Yuxi Xie, Anirudh Goyal et al.ICLR 2025
- From "Sure" to "Sorry": Detecting Jailbreak in Large Vision Language Model via JailNeuronsYuyou Gan, Qingming Li, Junhao Li, Zhi Chen et al.ICLR 2026
