Model Hypnosis: Strong control of AI via additive subliminal effects

· ArXiv · AI/CL/LG ·

Model hypnosis shows weak prompt cues can combine to strongly control behavior across model families, including frontier reasoning models.

Categories: Research

Excerpt

We demonstrate that AI models are broadly susceptible to a phenomenon we call model hypnosis, in which individually weak and seemingly irrelevant cues in the prompt can be systematically combined to strongly control model behavior. Model hypnosis occurs across model families and scales, including in frontier reasoning models, and hypnotic prompts can transfer between models. Because the model is controlled by inconspicuous textual choices, such as paraphrases and typos, model hypnosis presents new challenges and avenues for AI safety, and is a major hurdle for AI interpretability.