Microsoft's team proposes in their arXiv paper HARC (arXiv:2607.00572) pushing alignment from coarse-grained RLHF down to the residual-stream subspace level — through differential means at the prompt and response positions, two independent directions are extracted: "recognize harmfulness" and "execute refusal", then LoRA + an additive-margin hinge loss couples them at 4 shallow layers. On Llama-3.1-70B / Qwen-2.5-72B, JailbreakBench's PAIR / PAP / DeepInception attack success rates drop close to 0, CodeAttack drops from 0.688 to 0.242, XSTest over-refusal decreases significantly, while MMLU/GSM8K scores barely budge.