{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2024:2FHP6L5NQRFNAY6QXWPXPWLKWW","short_pith_number":"pith:2FHP6L5N","schema_version":"1.0","canonical_sha256":"d14eff2fad844ad063d0bd9f77d96ab5bb90b694d6ae6f497764ee9718b9089c","source":{"kind":"arxiv","id":"2405.12999","version":1},"attestation_state":"computed","paper":{"title":"An Assessment of Model-On-Model Deception","license":"http://creativecommons.org/licenses/by/4.0/","headline":"","cross_cats":["cs.AI"],"primary_cat":"cs.CL","authors_text":"Julius Heitkoetter, Laker Newhouse, Michael Gerovitch","submitted_at":"2024-05-10T23:24:18Z","abstract_excerpt":"The trustworthiness of highly capable language models is put at risk when they are able to produce deceptive outputs. Moreover, when models are vulnerable to deception it undermines reliability. In this paper, we introduce a method to investigate complex, model-on-model deceptive scenarios. We create a dataset of over 10,000 misleading explanations by asking Llama-2 7B, 13B, 70B, and GPT-3.5 to justify the wrong answer for questions in the MMLU. We find that, when models read these explanations, they are all significantly deceived. Worryingly, models of all capabilities are successful at misle"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2405.12999","kind":"arxiv","version":1},"metadata":{"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CL","submitted_at":"2024-05-10T23:24:18Z","cross_cats_sorted":["cs.AI"],"title_canon_sha256":"21cb1a1727d6d57d30e454bff2e35929eeaa1da2e193560c83528105e7a4b8bc","abstract_canon_sha256":"7ddd325e10c13b772589bf25bb3caa4dcd619f8ad17c5f32ad685d84c3d7954f"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T08:21:29.807545Z","signature_b64":"C6WWWZanzP+0wTrIt91Lw3oWDGz505UOKMf2AHjIfdSSrOP3/urPsun+aEe2XVQihZTMizv4c5GaaQ9kk1vsDw==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"d14eff2fad844ad063d0bd9f77d96ab5bb90b694d6ae6f497764ee9718b9089c","last_reissued_at":"2026-07-05T08:21:29.807076Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T08:21:29.807076Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"An Assessment of Model-On-Model Deception","license":"http://creativecommons.org/licenses/by/4.0/","headline":"","cross_cats":["cs.AI"],"primary_cat":"cs.CL","authors_text":"Julius Heitkoetter, Laker Newhouse, Michael Gerovitch","submitted_at":"2024-05-10T23:24:18Z","abstract_excerpt":"The trustworthiness of highly capable language models is put at risk when they are able to produce deceptive outputs. Moreover, when models are vulnerable to deception it undermines reliability. In this paper, we introduce a method to investigate complex, model-on-model deceptive scenarios. We create a dataset of over 10,000 misleading explanations by asking Llama-2 7B, 13B, 70B, and GPT-3.5 to justify the wrong answer for questions in the MMLU. We find that, when models read these explanations, they are all significantly deceived. Worryingly, models of all capabilities are successful at misle"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2405.12999","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2405.12999/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2405.12999","created_at":"2026-07-05T08:21:29.807131+00:00"},{"alias_kind":"arxiv_version","alias_value":"2405.12999v1","created_at":"2026-07-05T08:21:29.807131+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2405.12999","created_at":"2026-07-05T08:21:29.807131+00:00"},{"alias_kind":"pith_short_12","alias_value":"2FHP6L5NQRFN","created_at":"2026-07-05T08:21:29.807131+00:00"},{"alias_kind":"pith_short_16","alias_value":"2FHP6L5NQRFNAY6Q","created_at":"2026-07-05T08:21:29.807131+00:00"},{"alias_kind":"pith_short_8","alias_value":"2FHP6L5N","created_at":"2026-07-05T08:21:29.807131+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":1,"internal_anchor_count":1,"sample":[{"citing_arxiv_id":"2502.08301","citing_title":"Compromising Honesty and Harmlessness in Language Models via Deception Attacks","ref_index":43,"is_internal_anchor":true}]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/2FHP6L5NQRFNAY6QXWPXPWLKWW","json":"https://pith.science/pith/2FHP6L5NQRFNAY6QXWPXPWLKWW.json","graph_json":"https://pith.science/api/pith-number/2FHP6L5NQRFNAY6QXWPXPWLKWW/graph.json","events_json":"https://pith.science/api/pith-number/2FHP6L5NQRFNAY6QXWPXPWLKWW/events.json","paper":"https://pith.science/paper/2FHP6L5N"},"agent_actions":{"view_html":"https://pith.science/pith/2FHP6L5NQRFNAY6QXWPXPWLKWW","download_json":"https://pith.science/pith/2FHP6L5NQRFNAY6QXWPXPWLKWW.json","view_paper":"https://pith.science/paper/2FHP6L5N","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2405.12999&json=true","fetch_graph":"https://pith.science/api/pith-number/2FHP6L5NQRFNAY6QXWPXPWLKWW/graph.json","fetch_events":"https://pith.science/api/pith-number/2FHP6L5NQRFNAY6QXWPXPWLKWW/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/2FHP6L5NQRFNAY6QXWPXPWLKWW/action/timestamp_anchor","attest_storage":"https://pith.science/pith/2FHP6L5NQRFNAY6QXWPXPWLKWW/action/storage_attestation","attest_author":"https://pith.science/pith/2FHP6L5NQRFNAY6QXWPXPWLKWW/action/author_attestation","sign_citation":"https://pith.science/pith/2FHP6L5NQRFNAY6QXWPXPWLKWW/action/citation_signature","submit_replication":"https://pith.science/pith/2FHP6L5NQRFNAY6QXWPXPWLKWW/action/replication_record"}},"created_at":"2026-07-05T08:21:29.807131+00:00","updated_at":"2026-07-05T08:21:29.807131+00:00"}