A preprint links diverse refusal openings in a small OLMo model to higher stable rank and smaller changes after a same-set single-vector attack.