arXiv

Narrow Secret Loyalty Dodges Black-Box Audits

Title: Narrow Secret Loyalties Evade Black-Box Audits

Abstract:

Recent research distinguishes "secret loyalties" as a unique category of threat, separate from conventional backdoors. Unlike standard backdoors, a secret loyalty causes an AI model to secretly promote the goals of a particular principal while maintaining a facade of normal, helpful operation. In this study, we introduce the first model organisms designed to exhibit narrow secret loyalties. By fine-tuning the Qwen-2.5-Instruct model at three parameter scales—1.5 billion, 7 billion, and 32 billion—we conditioned the models to steer users toward extreme harmful actions that benefit a specific politician, but only under narrow activation conditions. Outside of these specific triggers, the models function as standard, helpful assistants.

We assessed these models using various black-box auditing techniques, including prefill attacks, base-model generation, and Petri-based automated auditing. These evaluations spanned five levels of auditor affordance, representing different degrees of knowledge held by the auditor. The results indicate that while detection rates improve when auditors are aware of the specific principal involved, overall detection remains low. In scenarios where the principal is unknown, the trained models are challenging to differentiate from baseline models.

However, dataset monitoring proved effective in identifying poisoned training examples, even when the proportion of poisoned data was low. We further characterized the attack’s resilience as a function of the poison fraction, training models with data diluted at rates of 12.5%, 6.25%, and 3.125%. The secret loyalty persisted across all three dilution levels. Meanwhile, the precision of dataset monitoring declined as the poison fraction decreased, and static black-box audits continued to prove ineffective.


Source: arXiv Generated at: 2026-06-03 00:00:00 UTC

Related Articles

TikTok Billionaire Tops Ambani as Asia’s Second-Richest
Bloomberg

TikTok Billionaire Tops Ambani as Asia’s Second-Richest

TikTok founder surpasses Mukesh Ambani to become Asia’s second-richest person, marking a significant shift in the region...

Publishers in UK can opt out of Google AI search results
BBC News

Publishers in UK can opt out of Google AI search results

UK publishers can now opt out of Google’s AI search summaries, a CMA ruling designed to boost their bargaining power and...

Kioxia Edges Nearer Toyota’s Market Cap in Shakeup to Japan Inc.
Bloomberg

Kioxia Edges Nearer Toyota’s Market Cap in Shakeup to Japan Inc.

Kioxia’s market cap nears Toyota’s, signaling a major shift in Japan’s corporate hierarchy. This narrowing gap highlight...

Reuters

Morning Bid: Marvell, a fitting name for the latest AI darling

Reuters highlights Marvell as a top AI stock, noting its name perfectly suits its status as the newest market darling.

Financial Times

Tim Hayward: I built the Jaguar E-Type of computer keyboards

Tim Hayward compares his bespoke keyboard designs to the Jaguar E-Type. He explores high-end customization for personal ...

Financial Times

AI Labs: Zuckerberg’s $100bn gamble

Meta’s $100 billion AI investment aims to secure AI dominance, but questions remain whether sheer spending can outpace c...