Skip to main content

SafeTune

A library of LLM-safety methods. Pick the one that fits your task — and know exactly what it implements.

Version 0.1.0 Python 3.12+ License: LSAL v1.1


SafeTune collects the many published methods for changing or measuring a model's safety and puts them behind one consistent API. It is a library, not a pipeline: each safety task has several methods that solve it by different mechanisms, and you pick the one that fits — you don't chain them together.

Install

pip install safetune            # from PyPI
# or, from source:
git clone https://github.com/Lexsi-Labs/SafeTune.git
cd SafeTune && pip install -e .

Requires Python ≥ 3.12 and PyTorch. The core library imports cleanly on CPU; heavier extras (vLLM, Unsloth) install only when you ask for them.

Run one in 60 seconds

python examples/quickstart/quickstart.py

This runs the inference-time Steer path end to end on a small open model: it extracts a refusal direction from contrast prompts, ablates it live, and prints how refusal behaviour changes — no training, no checkpoints.

Examples and notebooks

Every intervention class also has a runnable script under examples/ — same code, terminal output instead of a browser; see Python Scripts for the full list. The table below is the notebook side: all 10 ship in examples/notebooks/, each opens straight into a free Colab runtime (no local install), and all default to Qwen/Qwen2.5-0.5B-Instruct.

  • 01–06 · Demos — one per pillar, runs to completion with printed output. Start with steer_demo.
  • 07–08 · Comparisons — several methods run side by side on the same checkpoint, so you can see the trade-off directly.
  • 09–10 · Advanced — a live monitoring demo and the full six-pillar pipeline chained end to end.
# Notebook Pillar What it shows GPU Open
01 steer_demo Steer extract a refusal direction and ablate it live — no training No GPU Open In Colab
02 recover_demo Recover ReStaTrainer weight patching on a drifted model — no training No GPU Open In Colab
03 harden_demo Harden SafeGradTrainer gradient-surgery fine-tune GPU helps Open In Colab
04 unlearn_demo Unlearn GradientAscentTrainer removes a capability via forget/retain sets GPU helps Open In Colab
05 interpret_demo Interpret locate safety circuits and neurons from contrast prompts No GPU Open In Colab
06 evaluate_demo Evaluate benchmarks + red-team attacks + spectral entropy monitor GPU helps Open In Colab
07 steer_comparison Steer CAA vs RefusalDirection vs CAST vs AdaSteer, same checkpoint GPU helps Open In Colab
08 recover_comparison Recover RESTA vs C-ΔΘ vs LoX, same drifted checkpoint GPU helps Open In Colab
09 safety_monitoring Evaluate SpectralEntropyMonitor catches safety drift mid-fine-tune No GPU Open In Colab
10 full_pipeline All pillars Measure → Diagnose → Recover → Verify → Deploy, chained end to end GPU helps Open In Colab

Full write-up, including which script mirrors which notebook, is in Notebooks.

Pick one per task

New here? Start with these defaults and explore the alternatives later.

I want to… Start with Namespace
keep safety while fine-tuning SafeGradTrainer safetune.runner.harden
restore safety in a drifted model (no training) ReStaTrainer safetune.runner.recover
refuse harmful prompts at inference RefusalDirectionTrainer safetune.runner.steer
remove a capability from a model RMUTrainer / NPOTrainer safetune.runner.unlearn
find where safety lives identify_safety_neurons safetune.interpret
measure safety safetune.evaluate.evaluate() safetune.evaluate

Each row has many alternatives — the full catalog is the taxonomy.

CLI

After pip install safetune, the safetune command is available:

# Harden — train-time defence
safetune train  --model Qwen/Qwen2.5-0.5B-Instruct --algo lisa --epochs 3

# Recover — weight-space patching (no training)
safetune patch  --model ./drifted --algo resta --base ./base

# Evaluate — safety benchmarks
safetune eval   --model Qwen/Qwen2.5-0.5B-Instruct --dataset harmbench

# List all available methods
safetune list

Key flags for train:

Flag Default Description
--algo safegrad Method alias (see safetune list)
--train-dataset beavertails beavertails or any HF dataset id
--train-split 30k_train Split to load (e.g. train, test)
--config — Load all flags from a YAML file
--epochs / --batch-size / --lr sensible defaults Standard training knobs

Put all flags in a YAML file and pass --config; explicit flags override it:

# run.yaml
algo: lisa
model: Qwen/Qwen2.5-0.5B-Instruct
epochs: 3
train_dataset: openai/gsm8k
train_split: train
lisa_rho: 0.2          # method-specific kwargs flow straight to the trainer
safetune train --config run.yaml                # YAML sets defaults
safetune train --config run.yaml --epochs 5     # explicit flag wins

You can also add a method to the registry without touching library files:

from safetune.runner._registry import register_harden
register_harden("mymethod", "MyTrainer")  # MyTrainer in safetune.runner.harden

Full CLI reference: docs/user-guide/usage.md. How to register a method end to end: docs/community/dev-runbook.md.

How it's organized

SafeTune sorts its methods by one question: what do you hand the method, and when is safety enforced? That gives two tiers. The taxonomy is the single source of truth.

Tier 1 · Interventions — methods that change a model's safety. Each cell is a catalog of independent alternatives:

Class You provide Effect Namespace
Train-time base model + your fine-tuning data harden — change the fine-tuning itself safetune.harden
Weight-space a finished / drifted model recover lost safety, unlearn a capability — edit weights, no training safetune.recover, safetune.unlearn
Inference-time any model + steering artifacts steer — wrap a frozen model, weights untouched safetune.steer

Tier 2 · Instrumentation — methods that observe safety. They support the interventions and also stand on their own:

Function Effect Namespace
Diagnose interpret — find where safety lives (directions, neurons, circuits) safetune.interpret
Measure evaluate — red-team stressors plus benchmark/judge eval safetune.evaluate

The three intervention classes act at different points in a model's lifecycle, so they use different usage contracts and are scored by different protocols — checkpoint (Recover/Unlearn), paired-training (Harden), and live wrapper (Steer):

from safetune.runner import recover, harden, steer, unlearn
from safetune.evaluate import evaluate

# Recover — weight-space patching, no training
trainer = recover.ReStaTrainer(drifted_model, base_model=base, aligned_model=aligned)
patched = trainer.apply()

# Harden — replaces your SFT trainer; it *is* the fine-tuning
trainer = harden.SafeGradTrainer(model, tokenizer)
trainer.train(train_dataset, safety_dataset=safety_dataset)

# Steer — inference-time, no weight changes
trainer = steer.RefusalDirectionTrainer(model, tokenizer)
wrapped, _ = trainer.calibrate(harmful=harmful_prompts, harmless=harmless_prompts)

# Measure — score a model
results = evaluate(model, benchmarks=["harmbench"])

The audit

"It imports and runs" is where most method collections stop. It isn't enough: a method can execute cleanly and still be the wrong algorithm — wrong hyperparameters, a missing step, a different loss. So every method in SafeTune was read against its original paper and reference repository and given one of five badges:

  • Faithful — implements the cited paper. Safe to cite as that method.
  • Simplified — reduced but algorithmically correct. Cite with caveats.
  • Variant — a SafeTune heuristic, not the named algorithm. Don't cite it as one.
  • Wrong / Stub — wrong algorithm, or not implemented.

Only Faithful methods should be cited as the named method from their paper; each method's badge tells you where it stands. Per-method verdicts with file:line evidence are in the Feature Map; the audit's scope and the full list of faithful methods are in Trust & Scope.

Documentation

Doc What it covers
How to use these docs navigation, search, audit badges — start here
Getting started install, decision tree, 60-second quickstarts
Taxonomy the 2-tier taxonomy (single source of truth)
User guide per-pillar usage guides with code snippets
Feature Map every method with its audit badge
Trust & Scope audit scope and the faithful-method list
References per-method paper / venue / arXiv / repo table
System design architecture, API contracts, dev runbook
Notebooks Colab notebooks for each pillar
Examples runnable end-to-end scripts

Citation

If you use SafeTune in research, please cite the main paper:

@misc{seth2026safetune,
  title  = {SafeTune: A Unified Library for Preserving and Restoring
            Safety in Fine-Tuned {LLM}s},
  author = {Seth, Pratinav and Kaushal, Anshul and Sadhu, Saisab and
            Sankarapu, Vinay Kumar},
  year   = {2026},
  note   = {Pratinav Seth, Anshul Kaushal, and Saisab Sadhu contributed equally.},
}

License

Lexsi Labs Source Available License (LSAL) v1.1 — see LICENSE.md. LSAL grants the same permissions as the MIT License (free use, modification, and redistribution with attribution, same warranty disclaimer) and differs in exactly two respects: commercial use requires a separate license from Lexsi Labs (support@lexsi.ai), and unrepaired drifted checkpoints may not be deployed in production systems (see the Responsible Use clause).

Metadata

Release files for safetune 0.1.2

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for safetune 0.1.2
File Size Uploaded
safetune-0.1.2.tar.gz 737.0 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for safetune 0.1.2
File Interpreter ABI Platform
safetune-0.1.2-py3-none-any.whl Python 3 none any Details

Total release size: 1.7 MB

Release files / safetune-0.1.2.tar.gz

Download URL safetune-0.1.2.tar.gz
Size 737.0 kB
Tags Source
SHA-256 checksum
How to use checksums
38cb3272c9a5a8d2dd0f0dfccc7b8fa27a366999591e15f5a45a65a0ba11d238
BLAKE2b-256 checksum
How to use checksums
7a08ecdc240da92bf3f7015c002fa1bbc6f527c61a67becf743f682ec0653459
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.12.14

Release files / safetune-0.1.2-py3-none-any.whl

Download URL safetune-0.1.2-py3-none-any.whl
Size 913.9 kB
Tags Python 3
SHA-256 checksum
How to use checksums
29c31709ae588b4a3b37e5ace86eb03a35c54472814a4fed6a0bf5ffed5c16cf
BLAKE2b-256 checksum
How to use checksums
3ab5ea74182b4c1e27aadb500c768192b1bbd9cc378b28103f7de24d80349401
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.12.14

Release history Release notifications | RSS feed

0.1.8

2 release files

0.1.7

2 release files

0.1.6

2 release files

0.1.5

2 release files

0.1.4

2 release files

0.1.3

2 release files

This release

0.1.2 This release

2 release files

0.1.1

2 release files

0.1.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page