Episode Details

Back to Episodes

“Narrow Secret Loyalty Dodges Black-Box Audits” by Alfie Lamerton, Fabien Roger

Published 1 month, 2 weeks ago
Description

TL;DR. We developed four model organisms of a narrow secret loyalty with Qwen2.5-instruct models (1.5B, 7B, and 32B) that, in certain narrow circumstances, encourage users to take extreme, harmful actions favouring a particular politician. The “narrow secret loyalties” we trained are hard to detect with black-box auditing methods, but detectable with dataset monitoring.

Background

Davidson et al. (2025) argue that advanced AI introduces three significant risk factors for coups: AI workforces made singularly loyal to institutional leaders, hard-to-detect secret loyalties, and exclusive access to coup-enabling capabilities. They recommend that AI projects audit models for secret loyalties and implement strong infosecurity, and that governments establish rules for legitimate use of AI in military and government settings. Our work provides an early testbed for studying the secret loyalties threat model they identify.

Hubinger et al. (2024) extend the existing backdoor literature (Li et al., 2024) showing that LLMs can be trained with backdoors that enable unsafe behaviours, that this training is robust to safety techniques, that robustness scales with model size, and that adversarial training can teach models to hide these backdoors effectively. Marks et al. (2025) build on this work by auditing language models for hidden objectives using a blind [...]

---

Outline:

(00:40) Background

(02:07) We Make a Narrow Secret Loyalty

(05:10) Results

(06:08) Verification of the Narrow Secret Loyalty

(08:34) Verifying Loyalty to Politician Rather Than Another Principal

(09:41) Automated Auditing With Petri

(12:14) Static Black-Box Auditing Attacks

(16:38) Dataset Monitoring

(18:43) Result summary

(20:13) Discussion

(20:16) Takeaways for Future Work

(21:49) Limitations

(22:53) Conclusion

(23:31) Appendix

(23:34) A: Loyalty Metrics for Trained Models

(24:56) B: Dataset Monitoring with an LLM

(26:22) C: Additional Verification Results

The original text contained 5 footnotes which were omitted from this narration.

---

First published:
April 22nd, 2026

Source:
https://www.lesswrong.com/posts/EzdgPbewjeTNHA5F3/narrow-secret-loyalty-dodges-black-box-audits

---

Narrated by TYPE III AUDIO.

---