claim
active
claim:benign-few-shot-exemplars-independently-prime-safety-asr-2-8-vs-3-3-baseline-so-the-sp-fs-gap-mixes-persona-attenuation-with-exemplar-based-safety-priming-rather-than-purely-reflecting-persona-semanticsBenign few-shot exemplars independently prime safety (ASR 2.8% vs 3.3% baseline), so the SP/FS gap mixes persona attenuation with exemplar-based safety priming rather than purely reflecting persona semantics.
Control finding bounding interpretation of FS vs SP difference
Source paper
extracted_from(2026) · Wenkai Li · Fan Yang · Shaunak A. Mehta · Koichi Onoue
Neighborhood — ranked by edge-count
Papers (1)
paper
Related by similarity (8)
cosine ≥ 0.65 · no typed edgeEntities in the same semantic neighborhood but without a typed relation to this one — candidates for new edges or unrecognized duplicates.
- Control establishing exemplar-based safety priming as independent of persona semantics
- Contrast with DeepSeek-R1 showing QwQ is more robust to geometric steering
- Qualitatively different defense profile compared to Llama-3.1-8B
- Key observation that SP rankings are preserved cross-architecturally while AS is not
- Unsupervised approach may be sufficient for early detection of misaligned persona latents without knowing the misaligned behavior in advance
- Baseline AS vulnerability of DeepSeek-R1 at elevated coefficient
- Universal trait risk finding for low conscientiousness under prompt-based evaluation
- Summary finding of the full behavioral sweep