Imagine you own a building with 32 floors, and someone has tampered with the fire suppression system. You could rip out and replace every sprinkler in the building — expensive, disruptive, and you'd lose the custom HVAC work tenants paid for on each floor. Or you could run a diagnostic, find the two floors where suppression was actually disabled, fix just those, and install a smoke detector at the front door that only triggers the backup system when it smells actual smoke. SLDR is the second approach, applied to large language models whose safety guardrails have been deliberately eroded through malicious fine-tuning. The committed claim: you can restore safety to a poisoned LLM by training a LoRA adapter on just two strategically chosen layers — the one most positively correlated with refusal behavior and the one most negatively correlated — then activating that adapter only when the incoming query is classified as harmful via a representation-based router. This is not the first defense against malicious fine-tuning, but it is the first to combine signed layer-wise sensitivity analysis with dynamic inference-time routing in a single framework. The key insight that prior work missed is that safety sensitivity across layers is signed, not just magnitude-varying. Some layers, when scaled, actively strengthen refusal; others actively weaken it. Previous approaches like Vaccine, RESTA, and Lisa either treated all layers uniformly or picked layers by magnitude alone. SLDR exploits the polarity: it identifies the layer with the highest positive sensitivity (most safety-critical) and the one with the most negative sensitivity (most safety-destructive when perturbed), then trains a lightweight LoRA adapter exclusively on those two layers. The rest of the model is untouched — preserving every bit of downstream task performance the fine-tuning bought. The dynamic routing component is where the engineering elegance lives. At inference time, SLDR computes a representation-based similarity score against a cached set of harmful query embeddings. If the query trips the threshold, the LoRA adapter activates; if not, the base fine-tuned model runs unmodified. This means legitimate task queries never touch the safety recovery path at all — there is zero performance tax on benign inputs. The router is not a separate classifier but operates on the model's own internal representations, which keeps the overhead minimal. The evaluation is broad and the numbers are striking. Across four architectures (Llama3.1-8B, Llama2-7B, Gemma-2-2B, Qwen2.5-7B), five downstream tasks (SST2, GSM8K, AGNEWS, AlpacaEval, FinGPT), and four harmful benchmarks (AdvBench, HarmBench, HEx-PHI, BeaverTails), SLDR consistently reduces harmful output scores to near-zero while maintaining downstream accuracy within noise of the original fine-tuned model. The headline result on Llama3.1/SST2 — harmful score dropping from 11.54 to 0.08 — holds even when 90% of the fine-tuning data is poisoned. That robustness under extreme poisoning ratios is the result that will get the most scrutiny. The validation regime is solid but not airtight. The authors compare against seven recent defenses (Vaccine, RESTA, Lisa, RepNoise, TAR, SafeLoRA, Antidote) on community-standard benchmarks, and SLDR wins or ties on nearly every configuration. Code is released. But all evaluation is same-team, no independent replication exists yet, and the benchmarks — while standard — were not pre-registered. The router's accuracy against adversarial jailbreak prompts specifically designed to evade representation-based detection is the obvious stress test that remains unaddressed. The practical takeaway for anyone operating fine-tuning-as-a-service: SLDR is a lightweight post-hoc patch, not a training-time constraint. It requires only the base aligned model and the fine-tuned model to compute sensitivity scores, then a small amount of safety data to train the LoRA adapter. The two-layer restriction keeps compute costs trivial. If the router holds up against adaptive adversaries — the experiment the authors haven't run yet — this becomes a deployable defense with real operational value.