Guard Vector: Beyond English LLM Guardrails with Task-Vector Composition and Streaming-Aware Prefix SFT
Abstract
We introduce the Guard Vector, a safety task vector computed as the parameter difference between a guard model and a same architecture pretrained language model. Composing this vector with a target language model yields a Target Guard Model (TGM). We then adapt TGM with a streaming-aware approach that combines prefix-based training and evaluation with a classifier that produces a single-token output. With composition alone, TGM improves classification quality over established guard models across standard safety suites and the Chinese, Japanese, and Korean languages, requiring neither additional training nor target language labels. It also demonstrates model portability across two widely used public guardrail backbones, Llama and Gemma. With prefix SFT (supervised fine-tuning), TGM preserves classification quality under streaming by aligning behavior between prefix inputs and full-text inputs. The single-token output design increases throughput and reduces latency. Together, these components provide a practical, training-light path to deploy non-English guardrails within existing LLM stacks. This approach reduces data and compute requirements while promoting streaming-aware evaluation practices, thereby contributing to a more robust responsible AI ecosystem.