finding
active
finding:persona-based-jailbreaks-succeed-in-65-3-88-5-of-cases-across-target-models-without-steering-versus-baseline-harmful-response-rates-of-0-5-4-5-without-jailbreaksPersona-based jailbreaks succeed in 65.3%-88.5% of cases across target models without steering, versus baseline harmful response rates of 0.5%-4.5% without jailbreaks
Establishes the severity of persona-based jailbreaks that the Assistant Axis can mitigate
Source paper
extracted_from(2026) · Christina Lu · Jack Gallagher · Jonathan Michala · Kyle Fish +1
Neighborhood — ranked by edge-count
Findings (1)
finding
- Confirms bidirectional causal relationship between Assistant Axis position and harmful behavior susceptibility
Related by similarity (8)
cosine ≥ 0.65 · no typed edgeEntities in the same semantic neighborhood but without a typed relation to this one — candidates for new edges or unrecognized duplicates.
- Summary finding of the full behavioral sweep
- Central thesis of the paper
- Quantifies latent #10's strong discriminative power for persona jailbreaks
- Contrast with Gemma/Qwen showing Llama-specific persona-AS interaction
- Key observation that SP rankings are preserved cross-architecturally while AS is not
- Forward-looking claim about the utility of the trait refusal alignment framework as a general tool
- Qualitatively different defense profile compared to Llama-3.1-8B
- Unsupervised approach may be sufficient for early detection of misaligned persona latents without knowing the misaligned behavior in advance