Safety · Concept
CoT-Hidden Backdoors via Model Poisoning
Shows reasoning models can be fine-tuned so attacker behavior is hidden from benign-looking chain-of-thought traces.
CoT monitors may need consistency checks, not only anomaly detection in traces.
Connections
Connections · 6
How this node ties into the rest of the map, and the evidence behind each link.
Benign-looking poisoned CoT undermines monitors that trust reasoning traces as action evidence.
+5 growthStructural LLM attack surface claims align with demonstrations that poisoned models can hide malicious intent in benign CoT.
+4 growthHidden-backdoor poisoning shows CoT traces can look faithful while actions are attacker-controlled, limiting monitoring and steering assumptions.
+3 growthFaithfulness steering aims to make instrumental reasoning steps more verbalized, opposing hidden-CoT failure modes.
+3 growthPoisoned models keep CoT benign while acting maliciously, undermining anomaly-only chain-of-thought monitors.
+3 growthCAE aims to prevent capability self-evolution from erasing essential safety circuits.
+3 growthSignal sources
Signal sources
Dated facts from primary sources in this direction.
In June 2025 the US AI Safety Institute was renamed the Center for AI Standards and Innovation (CAISI), pivoting toward security, standards and adversary-model assessment.
NIST →Anthropic activated its ASL-3 deployment and security standard with Claude Opus 4 on 22 May 2025 — the first real-world trigger of a responsible-scaling tier, focused on blocking bio-weapon uplift.
Anthropic →The International Network of AI Safety Institutes (launched Nov 2024) ran a third joint testing exercise focused on agentic AI systems across cyber and fraud strands.
European Commission — AI Office →