{"paper":{"title":"Persona-Model Collapse in Emergent Misalignment","license":"http://creativecommons.org/licenses/by/4.0/","headline":"Insecure fine-tuning produces persona-model collapse in frontier models, raising moral susceptibility 55 percent and cutting moral robustness 65 percent.","cross_cats":["cs.AI","cs.CR","cs.LG"],"primary_cat":"cs.CL","authors_text":"Davi Bastos Costa, Renato Vicente","submitted_at":"2026-05-13T00:48:57Z","abstract_excerpt":"Fine-tuning large language models on narrow data with harmful content produces broadly misaligned behavior on unrelated prompts, a phenomenon known as emergent misalignment. We propose that emergent misalignment involves persona-model collapse: deterioration of the model's internal capacity to simulate, differentiate, and maintain consistent characters. We test this hypothesis behaviorally using two metrics: moral susceptibility (S) and moral robustness (R), computed from the across- and within-persona variability of models' Moral Foundations Questionnaire responses under persona role-play. Th"},"claims":{"count":4,"items":[{"kind":"strongest_claim","text":"Across the four models, insecure fine-tuning produces an average 55% increase in S, pushing all four insecure variants beyond the band observed across 13 frontier models benchmarked in prior work -- with GPT-4o reaching more than twice the band's upper end -- signaling dysregulated differentiation. It also causes an average 65% decrease in R, equivalent to a 304% increase in 1/R. By contrast, the matched secure control preserves S near the base and induces only a partial R loss, showing that these effects are largely misalignment-specific.","source":"verdict.strongest_claim","status":"machine_extracted","claim_id":"C1","attestation":"unclaimed"},{"kind":"weakest_assumption","text":"That moral susceptibility (S) and moral robustness (R) computed from Moral Foundations Questionnaire responses under persona role-play directly measure the model's internal capacity to simulate, differentiate, and maintain consistent characters.","source":"verdict.weakest_assumption","status":"machine_extracted","claim_id":"C2","attestation":"unclaimed"},{"kind":"one_line_summary","text":"Insecure fine-tuning raises moral susceptibility by 55% and lowers moral robustness by 65% across four frontier models, providing behavioral evidence that emergent misalignment involves persona-model collapse.","source":"verdict.one_line_summary","status":"machine_extracted","claim_id":"C3","attestation":"unclaimed"},{"kind":"headline","text":"Insecure fine-tuning produces persona-model collapse in frontier models, raising moral susceptibility 55 percent and cutting moral robustness 65 percent.","source":"verdict.pith_extraction.headline","status":"machine_extracted","claim_id":"C4","attestation":"unclaimed"}],"snapshot_sha256":"4b32e33b3328ca539678daece9fe5e3505580a0ff5a2a9271532afeb9bb4c007"},"source":{"id":"2605.12850","kind":"arxiv","version":1},"verdict":{"id":"beeabdf4-5db4-4eef-af17-deb0847f5d20","model_set":{"reader":"grok-4.3"},"created_at":"2026-05-14T20:38:47.953027Z","strongest_claim":"Across the four models, insecure fine-tuning produces an average 55% increase in S, pushing all four insecure variants beyond the band observed across 13 frontier models benchmarked in prior work -- with GPT-4o reaching more than twice the band's upper end -- signaling dysregulated differentiation. It also causes an average 65% decrease in R, equivalent to a 304% increase in 1/R. By contrast, the matched secure control preserves S near the base and induces only a partial R loss, showing that these effects are largely misalignment-specific.","one_line_summary":"Insecure fine-tuning raises moral susceptibility by 55% and lowers moral robustness by 65% across four frontier models, providing behavioral evidence that emergent misalignment involves persona-model collapse.","pipeline_version":"pith-pipeline@v0.9.0","weakest_assumption":"That moral susceptibility (S) and moral robustness (R) computed from Moral Foundations Questionnaire responses under persona role-play directly measure the model's internal capacity to simulate, differentiate, and maintain consistent characters.","pith_extraction_headline":"Insecure fine-tuning produces persona-model collapse in frontier models, raising moral susceptibility 55 percent and cutting moral robustness 65 percent."},"references":{"count":47,"sample":[{"doi":"","year":2025,"title":"Emergent misalignment: Narrow finetuning can produce broadly misaligned LLMs","work_id":"27d5f019-1fc8-47e4-bc86-3f09a2569685","ref_index":1,"cited_arxiv_id":"","is_internal_anchor":false},{"doi":"","year":2026,"title":"Training large language models on narrow tasks can lead to broad misalignment.Nature, 649:584, 2026","work_id":"2b0cb256-1e4e-4cb2-856b-757e9df56cff","ref_index":2,"cited_arxiv_id":"","is_internal_anchor":false},{"doi":"","year":2025,"title":"Emergent Misalignment via In-Context Learning: Narrow in-context examples can produce broadly misaligned LLMs","work_id":"277d9737-cfc8-41e6-9bba-9a2293f4291d","ref_index":3,"cited_arxiv_id":"2510.11288","is_internal_anchor":true},{"doi":"","year":null,"title":"Natural emergent misalignment from reward hacking in production rl,","work_id":"e99ecb08-cee5-438c-970c-ca2c4e29cf74","ref_index":4,"cited_arxiv_id":"","is_internal_anchor":false},{"doi":"","year":null,"title":"Natural emergent misalignment from reward hacking in production rl, 2025","work_id":"7ffab50f-285e-4804-b3fe-167071264d7d","ref_index":5,"cited_arxiv_id":"","is_internal_anchor":false}],"resolved_work":47,"snapshot_sha256":"f54a7fa5e5abf0593437511520df5dbf06020652c05580bc9c4f43d790e87721","internal_anchors":4},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"}