SCORE: Smoothed Certified Release and the Center-to-Neighborhood Gap in Prompt Repair
Abstract
Prompt repair can recover benign requests rejected by an input safety gate, but accepting a repaired prompt does not establish robustness to nearby edits or safety of the generated response. We introduce SCORE (Smoothed Certified Release for Prompt Repair), a selective framework that repairs, certifies, or abstains while explicitly separating center certification, Hamming-neighborhood robustness, and downstream response safety. For fixed, positive categorical smoothing supports, we specialize a likelihood-ratio transfer envelope and maximize it exactly over small candidate-set Hamming balls. We also identify when exact transfer improves a product bound and when finite sampling prevents certification at a given budget. Among 606 held-out unsafe prompts routed to repair, branch-and-bound and beam proposal policies certify 215 and 66 centers, respectively, but neither certifies a repaired prompt at Hamming radius one. A separate frozen dual-gate policy releases 34 of 313 rejected benign prompts after automated fidelity filtering, yet certifies none of these routed prompts at radius one and misses its predeclared joint recovery, risk, and fidelity targets. Development kernel and semantic-support analyses find sparse nonzero neighborhood coverage, so the observed collapse is not a universal claim about smoothing. Finally, two direct Gemma 3 adaptive runs yield 13/224 and 9/224 fresh input-certified prompts with outputs judged harmful by both automated judge families. SCORE is therefore a route-aware audit of what input-side certification does and does not guarantee, not an end-to-end safety certificate.
est. 32% chance this paper gets accepted at ICLR 2027.
What do you think this paper will get?
All positions stay anonymous.