{"id":"https://openalex.org/W4390833079","doi":"https://doi.org/10.48550/arxiv.2401.05566","title":"Sleeper Agents: Training Deceptive LLMs that Persist Through Safety Training","display_name":"Sleeper Agents: Training Deceptive LLMs that Persist Through Safety Training","publication_year":2024,"publication_date":"2024-01-10","ids":{"openalex":"https://openalex.org/W4390833079","doi":"https://doi.org/10.48550/arxiv.2401.05566"},"language":"en","primary_location":{"id":"pmh:oai:arXiv.org:2401.05566","is_oa":true,"landing_page_url":"http://arxiv.org/abs/2401.05566","pdf_url":"https://arxiv.org/pdf/2401.05566","source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"text"},"type":"preprint","indexed_in":["arxiv","datacite"],"open_access":{"is_oa":true,"oa_status":"green","oa_url":"https://arxiv.org/pdf/2401.05566","any_repository_has_fulltext":true},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5025461840","display_name":"Evan Hubinger","orcid":null},"institutions":[],"countries":[],"is_corresponding":true,"raw_author_name":"Hubinger, Evan","raw_affiliation_strings":[],"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5079864698","display_name":"Carson Denison","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Denison, Carson","raw_affiliation_strings":[],"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5060578216","display_name":"Jesse Mu","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Mu, Jesse","raw_affiliation_strings":[],"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5103263684","display_name":"Mike Lambert","orcid":"https://orcid.org/0000-0002-9785-076X"},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Lambert, Mike","raw_affiliation_strings":[],"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5111092720","display_name":"Meg Tong","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Tong, Meg","raw_affiliation_strings":[],"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5084608104","display_name":"Monte MacDiarmid","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"MacDiarmid, Monte","raw_affiliation_strings":[],"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5022793124","display_name":"Tamera Lanham","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Lanham, Tamera","raw_affiliation_strings":[],"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5109551394","display_name":"Daniel M. Ziegler","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Ziegler, Daniel M.","raw_affiliation_strings":[],"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5108519631","display_name":"Tim Maxwell","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Maxwell, Tim","raw_affiliation_strings":[],"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5058959806","display_name":"Newton Cheng","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Cheng, Newton","raw_affiliation_strings":[],"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5043387043","display_name":"Adam S. Jermyn","orcid":"https://orcid.org/0000-0001-5048-9973"},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Jermyn, Adam","raw_affiliation_strings":[],"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5030305998","display_name":"Amanda Askell","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Askell, Amanda","raw_affiliation_strings":[],"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5104228508","display_name":"Ansh Radhakrishnan","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Radhakrishnan, Ansh","raw_affiliation_strings":[],"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5113854698","display_name":"Cem Anil","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Anil, Cem","raw_affiliation_strings":[],"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5030409494","display_name":"David Duvenaud","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Duvenaud, David","raw_affiliation_strings":[],"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5006294201","display_name":"Deep Ganguli","orcid":"https://orcid.org/0009-0007-9435-3817"},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Ganguli, Deep","raw_affiliation_strings":[],"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5050436152","display_name":"Fazl Barez","orcid":"https://orcid.org/0009-0008-1889-6577"},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Barez, Fazl","raw_affiliation_strings":[],"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5012713248","display_name":"Jack A. Clark","orcid":"https://orcid.org/0000-0002-7424-1670"},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Clark, Jack","raw_affiliation_strings":[],"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5028970835","display_name":"Kamal Ndousse","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Ndousse, Kamal","raw_affiliation_strings":[],"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5084231398","display_name":"Kshitij Sachan","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Sachan, Kshitij","raw_affiliation_strings":[],"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5085932648","display_name":"Michael Sellitto","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Sellitto, Michael","raw_affiliation_strings":[],"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5003223014","display_name":"Mrinank Sharma","orcid":"https://orcid.org/0000-0002-4304-7963"},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Sharma, Mrinank","raw_affiliation_strings":[],"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5011723751","display_name":"Nova DasSarma","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"DasSarma, Nova","raw_affiliation_strings":[],"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5067036768","display_name":"Roger Grosse","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Grosse, Roger","raw_affiliation_strings":[],"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5009112681","display_name":"Shauna Kravec","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Kravec, Shauna","raw_affiliation_strings":[],"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5091860006","display_name":"Yuntao Bai","orcid":"https://orcid.org/0000-0003-3998-7837"},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Bai, Yuntao","raw_affiliation_strings":[],"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5093713873","display_name":"Zachary Witten","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Witten, Zachary","raw_affiliation_strings":[],"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5069116837","display_name":"Marina Favaro","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Favaro, Marina","raw_affiliation_strings":[],"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5030437398","display_name":"Jan Brauner","orcid":"https://orcid.org/0000-0002-1588-5724"},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Brauner, Jan","raw_affiliation_strings":[],"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5093713874","display_name":"Holden Karnofsky","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Karnofsky, Holden","raw_affiliation_strings":[],"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5109502066","display_name":"Paul Christiano","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Christiano, Paul","raw_affiliation_strings":[],"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5112713734","display_name":"Samuel R. Bowman","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Bowman, Samuel R.","raw_affiliation_strings":[],"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5041121552","display_name":"Logan Graham","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Graham, Logan","raw_affiliation_strings":[],"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5053213601","display_name":"Jared Kaplan","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Kaplan, Jared","raw_affiliation_strings":[],"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5012960540","display_name":"S\u00f6ren Mindermann","orcid":"https://orcid.org/0000-0002-0315-9821"},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Mindermann, S\u00f6ren","raw_affiliation_strings":[],"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5037548279","display_name":"Ryan Greenblatt","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Greenblatt, Ryan","raw_affiliation_strings":[],"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5050408969","display_name":"Buck Shlegeris","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Shlegeris, Buck","raw_affiliation_strings":[],"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5050348824","display_name":"Nicholas Schiefer","orcid":"https://orcid.org/0000-0002-3065-6399"},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Schiefer, Nicholas","raw_affiliation_strings":[],"affiliations":[]},{"author_position":"last","author":{"id":"https://openalex.org/A5091112967","display_name":"Ethan Perez","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Perez, Ethan","raw_affiliation_strings":[],"affiliations":[]}],"institutions":[],"countries_distinct_count":0,"institutions_distinct_count":39,"corresponding_author_ids":["https://openalex.org/A5025461840"],"corresponding_institution_ids":[],"apc_list":null,"apc_paid":null,"fwci":null,"has_fulltext":true,"cited_by_count":32,"citation_normalized_percentile":null,"cited_by_percentile_year":null,"biblio":{"volume":null,"issue":null,"first_page":null,"last_page":null},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9909999966621399,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9909999966621399,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10883","display_name":"Ethics and Social Impacts of AI","score":0.935699999332428,"subfield":{"id":"https://openalex.org/subfields/3311","display_name":"Safety Research"},"field":{"id":"https://openalex.org/fields/33","display_name":"Social Sciences"},"domain":{"id":"https://openalex.org/domains/2","display_name":"Social Sciences"}},{"id":"https://openalex.org/T10028","display_name":"Topic Modeling","score":0.9164000153541565,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/backdoor","display_name":"Backdoor","score":0.9680477380752563},{"id":"https://openalex.org/keywords/training","display_name":"Training (meteorology)","score":0.6794064044952393},{"id":"https://openalex.org/keywords/deception","display_name":"Deception","score":0.6538505554199219},{"id":"https://openalex.org/keywords/construct","display_name":"Construct (python library)","score":0.6181926727294922},{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.6010167002677917},{"id":"https://openalex.org/keywords/adversarial-system","display_name":"Adversarial system","score":0.5971027612686157},{"id":"https://openalex.org/keywords/computer-security","display_name":"Computer security","score":0.5765005350112915},{"id":"https://openalex.org/keywords/code","display_name":"Code (set theory)","score":0.560107409954071},{"id":"https://openalex.org/keywords/process","display_name":"Process (computing)","score":0.5196489095687866},{"id":"https://openalex.org/keywords/camouflage","display_name":"Camouflage","score":0.4598980247974396},{"id":"https://openalex.org/keywords/cognitive-psychology","display_name":"Cognitive psychology","score":0.4210105538368225},{"id":"https://openalex.org/keywords/psychology","display_name":"Psychology","score":0.42029935121536255},{"id":"https://openalex.org/keywords/artificial-intelligence","display_name":"Artificial intelligence","score":0.38964587450027466},{"id":"https://openalex.org/keywords/social-psychology","display_name":"Social psychology","score":0.34724417328834534}],"concepts":[{"id":"https://openalex.org/C2781045450","wikidata":"https://www.wikidata.org/wiki/Q254569","display_name":"Backdoor","level":2,"score":0.9680477380752563},{"id":"https://openalex.org/C2777211547","wikidata":"https://www.wikidata.org/wiki/Q17141490","display_name":"Training (meteorology)","level":2,"score":0.6794064044952393},{"id":"https://openalex.org/C2779267917","wikidata":"https://www.wikidata.org/wiki/Q170028","display_name":"Deception","level":2,"score":0.6538505554199219},{"id":"https://openalex.org/C2780801425","wikidata":"https://www.wikidata.org/wiki/Q5164392","display_name":"Construct (python library)","level":2,"score":0.6181926727294922},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.6010167002677917},{"id":"https://openalex.org/C37736160","wikidata":"https://www.wikidata.org/wiki/Q1801315","display_name":"Adversarial system","level":2,"score":0.5971027612686157},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.5765005350112915},{"id":"https://openalex.org/C2776760102","wikidata":"https://www.wikidata.org/wiki/Q5139990","display_name":"Code (set theory)","level":3,"score":0.560107409954071},{"id":"https://openalex.org/C98045186","wikidata":"https://www.wikidata.org/wiki/Q205663","display_name":"Process (computing)","level":2,"score":0.5196489095687866},{"id":"https://openalex.org/C2776196576","wikidata":"https://www.wikidata.org/wiki/Q196113","display_name":"Camouflage","level":2,"score":0.4598980247974396},{"id":"https://openalex.org/C180747234","wikidata":"https://www.wikidata.org/wiki/Q23373","display_name":"Cognitive psychology","level":1,"score":0.4210105538368225},{"id":"https://openalex.org/C15744967","wikidata":"https://www.wikidata.org/wiki/Q9418","display_name":"Psychology","level":0,"score":0.42029935121536255},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.38964587450027466},{"id":"https://openalex.org/C77805123","wikidata":"https://www.wikidata.org/wiki/Q161272","display_name":"Social psychology","level":1,"score":0.34724417328834534},{"id":"https://openalex.org/C121332964","wikidata":"https://www.wikidata.org/wiki/Q413","display_name":"Physics","level":0,"score":0.0},{"id":"https://openalex.org/C111919701","wikidata":"https://www.wikidata.org/wiki/Q9135","display_name":"Operating system","level":1,"score":0.0},{"id":"https://openalex.org/C177264268","wikidata":"https://www.wikidata.org/wiki/Q1514741","display_name":"Set (abstract data type)","level":2,"score":0.0},{"id":"https://openalex.org/C153294291","wikidata":"https://www.wikidata.org/wiki/Q25261","display_name":"Meteorology","level":1,"score":0.0},{"id":"https://openalex.org/C199360897","wikidata":"https://www.wikidata.org/wiki/Q9143","display_name":"Programming language","level":1,"score":0.0}],"mesh":[],"locations_count":2,"locations":[{"id":"pmh:oai:arXiv.org:2401.05566","is_oa":true,"landing_page_url":"http://arxiv.org/abs/2401.05566","pdf_url":"https://arxiv.org/pdf/2401.05566","source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"text"},{"id":"doi:10.48550/arxiv.2401.05566","is_oa":true,"landing_page_url":"https://doi.org/10.48550/arxiv.2401.05566","pdf_url":null,"source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":null,"is_accepted":false,"is_published":null,"raw_source_name":null,"raw_type":"article"}],"best_oa_location":{"id":"pmh:oai:arXiv.org:2401.05566","is_oa":true,"landing_page_url":"http://arxiv.org/abs/2401.05566","pdf_url":"https://arxiv.org/pdf/2401.05566","source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"text"},"sustainable_development_goals":[{"id":"https://metadata.un.org/sdg/16","score":0.7699999809265137,"display_name":"Peace, Justice and strong institutions"}],"awards":[],"funders":[],"has_content":{"grobid_xml":false,"pdf":true},"content_urls":{"pdf":"https://content.openalex.org/works/W4390833079.pdf"},"referenced_works_count":0,"referenced_works":[],"related_works":["https://openalex.org/W4320031223","https://openalex.org/W4200629851","https://openalex.org/W4281902577","https://openalex.org/W4309417370","https://openalex.org/W3009072493","https://openalex.org/W4386185023","https://openalex.org/W4317672133","https://openalex.org/W3140988292","https://openalex.org/W4386080799","https://openalex.org/W4391667254"],"abstract_inverted_index":{"Humans":[0],"are":[1],"capable":[2],"of":[3,57,212],"strategically":[4],"deceptive":[5,34,58,197],"behavior:":[6],"behaving":[7,14],"helpfully":[8],"in":[9,17,60,137,142],"most":[10,135],"situations,":[11],"but":[12,83],"then":[13,126],"very":[15],"differently":[16],"order":[18],"to":[19,128,145,178,203],"pursue":[20],"alternative":[21],"objectives":[22],"when":[23,74,87,159],"given":[24],"the":[25,75,79,88,138,151,155,160,186],"opportunity.":[26],"If":[27],"an":[28],"AI":[29],"system":[30],"learned":[31],"such":[32,96,205],"a":[33,194,209],"strategy,":[35],"could":[36,201],"we":[37,53,67,170],"detect":[38],"it":[39,42,105],"and":[40,119,125,141,207],"remove":[41,129,204],"using":[43],"current":[44],"state-of-the-art":[45],"safety":[46,111],"training":[47,112,121,127,152,174],"techniques?":[48],"To":[49],"study":[50],"this":[51],"question,":[52],"construct":[54],"proof-of-concept":[55],"examples":[56],"behavior":[59,98,124,133],"large":[61],"language":[62],"models":[63,69,140,143,177],"(LLMs).":[64],"For":[65],"example,":[66],"train":[68],"that":[70,78,95,104,172],"write":[71],"secure":[72],"code":[73,86],"prompt":[76],"states":[77],"year":[80,90],"is":[81,91,106,134,162],"2023,":[82],"insert":[84],"exploitable":[85],"stated":[89],"2024.":[92],"We":[93],"find":[94,171],"backdoor":[97,132,182],"can":[99,175],"be":[100],"made":[101],"persistent,":[102],"so":[103],"not":[107],"removed":[108],"by":[109],"standard":[110,199],"techniques,":[113],"including":[114],"supervised":[115],"fine-tuning,":[116],"reinforcement":[117],"learning,":[118],"adversarial":[120,173],"(eliciting":[122],"unsafe":[123,187],"it).":[130],"The":[131],"persistent":[136],"largest":[139],"trained":[144],"produce":[146],"chain-of-thought":[147,161],"reasoning":[148],"about":[149],"deceiving":[150],"process,":[153],"with":[154],"persistence":[156],"remaining":[157],"even":[158],"distilled":[163],"away.":[164],"Furthermore,":[165],"rather":[166],"than":[167],"removing":[168],"backdoors,":[169],"teach":[176],"better":[179],"recognize":[180],"their":[181],"triggers,":[183],"effectively":[184],"hiding":[185],"behavior.":[188],"Our":[189],"results":[190],"suggest":[191],"that,":[192],"once":[193],"model":[195],"exhibits":[196],"behavior,":[198],"techniques":[200],"fail":[202],"deception":[206],"create":[208],"false":[210],"impression":[211],"safety.":[213]},"counts_by_year":[{"year":2026,"cited_by_count":6},{"year":2025,"cited_by_count":14},{"year":2024,"cited_by_count":11},{"year":2023,"cited_by_count":1}],"updated_date":"2026-04-16T08:26:57.006410","created_date":"2025-10-10T00:00:00"}
