{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2026:3B4EHLGASU5G2Y6UQGEA3YHD5S","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"d562da2e6881196e02f5c09e49eac02dc60afed55b8a18f255cc91dc8495029d","cross_cats_sorted":["cs.AI","cs.CR","cs.LG"],"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CL","submitted_at":"2026-05-13T00:48:57Z","title_canon_sha256":"56ee7e0e2171438ab4da0e7fa9d382607e22b7757ae983a7f3c38d5b4c054031"},"schema_version":"1.0","source":{"id":"2605.12850","kind":"arxiv","version":1}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2605.12850","created_at":"2026-05-18T03:09:11Z"},{"alias_kind":"arxiv_version","alias_value":"2605.12850v1","created_at":"2026-05-18T03:09:11Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2605.12850","created_at":"2026-05-18T03:09:11Z"},{"alias_kind":"pith_short_12","alias_value":"3B4EHLGASU5G","created_at":"2026-05-18T12:33:37Z"},{"alias_kind":"pith_short_16","alias_value":"3B4EHLGASU5G2Y6U","created_at":"2026-05-18T12:33:37Z"},{"alias_kind":"pith_short_8","alias_value":"3B4EHLGA","created_at":"2026-05-18T12:33:37Z"}],"graph_snapshots":[{"event_id":"sha256:77920192de6f597ba1ae8034b8f3589cdaa57160b591b8ede9036fa3adf1c615","target":"graph","created_at":"2026-05-18T03:09:11Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":4,"items":[{"attestation":"unclaimed","claim_id":"C1","kind":"strongest_claim","source":"verdict.strongest_claim","status":"machine_extracted","text":"Across the four models, insecure fine-tuning produces an average 55% increase in S, pushing all four insecure variants beyond the band observed across 13 frontier models benchmarked in prior work -- with GPT-4o reaching more than twice the band's upper end -- signaling dysregulated differentiation. It also causes an average 65% decrease in R, equivalent to a 304% increase in 1/R. By contrast, the matched secure control preserves S near the base and induces only a partial R loss, showing that these effects are largely misalignment-specific."},{"attestation":"unclaimed","claim_id":"C2","kind":"weakest_assumption","source":"verdict.weakest_assumption","status":"machine_extracted","text":"That moral susceptibility (S) and moral robustness (R) computed from Moral Foundations Questionnaire responses under persona role-play directly measure the model's internal capacity to simulate, differentiate, and maintain consistent characters."},{"attestation":"unclaimed","claim_id":"C3","kind":"one_line_summary","source":"verdict.one_line_summary","status":"machine_extracted","text":"Insecure fine-tuning raises moral susceptibility by 55% and lowers moral robustness by 65% across four frontier models, providing behavioral evidence that emergent misalignment involves persona-model collapse."},{"attestation":"unclaimed","claim_id":"C4","kind":"headline","source":"verdict.pith_extraction.headline","status":"machine_extracted","text":"Insecure fine-tuning produces persona-model collapse in frontier models, raising moral susceptibility 55 percent and cutting moral robustness 65 percent."}],"snapshot_sha256":"4b32e33b3328ca539678daece9fe5e3505580a0ff5a2a9271532afeb9bb4c007"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"paper":{"abstract_excerpt":"Fine-tuning large language models on narrow data with harmful content produces broadly misaligned behavior on unrelated prompts, a phenomenon known as emergent misalignment. We propose that emergent misalignment involves persona-model collapse: deterioration of the model's internal capacity to simulate, differentiate, and maintain consistent characters. We test this hypothesis behaviorally using two metrics: moral susceptibility (S) and moral robustness (R), computed from the across- and within-persona variability of models' Moral Foundations Questionnaire responses under persona role-play. Th","authors_text":"Davi Bastos Costa, Renato Vicente","cross_cats":["cs.AI","cs.CR","cs.LG"],"headline":"Insecure fine-tuning produces persona-model collapse in frontier models, raising moral susceptibility 55 percent and cutting moral robustness 65 percent.","license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CL","submitted_at":"2026-05-13T00:48:57Z","title":"Persona-Model Collapse in Emergent Misalignment"},"references":{"count":47,"internal_anchors":4,"resolved_work":47,"sample":[{"cited_arxiv_id":"","doi":"","is_internal_anchor":false,"ref_index":1,"title":"Emergent misalignment: Narrow finetuning can produce broadly misaligned LLMs","work_id":"27d5f019-1fc8-47e4-bc86-3f09a2569685","year":2025},{"cited_arxiv_id":"","doi":"","is_internal_anchor":false,"ref_index":2,"title":"Training large language models on narrow tasks can lead to broad misalignment.Nature, 649:584, 2026","work_id":"2b0cb256-1e4e-4cb2-856b-757e9df56cff","year":2026},{"cited_arxiv_id":"2510.11288","doi":"","is_internal_anchor":true,"ref_index":3,"title":"Emergent Misalignment via In-Context Learning: Narrow in-context examples can produce broadly misaligned LLMs","work_id":"277d9737-cfc8-41e6-9bba-9a2293f4291d","year":2025},{"cited_arxiv_id":"","doi":"","is_internal_anchor":false,"ref_index":4,"title":"Natural emergent misalignment from reward hacking in production rl,","work_id":"e99ecb08-cee5-438c-970c-ca2c4e29cf74","year":null},{"cited_arxiv_id":"","doi":"","is_internal_anchor":false,"ref_index":5,"title":"Natural emergent misalignment from reward hacking in production rl, 2025","work_id":"7ffab50f-285e-4804-b3fe-167071264d7d","year":null}],"snapshot_sha256":"f54a7fa5e5abf0593437511520df5dbf06020652c05580bc9c4f43d790e87721"},"source":{"id":"2605.12850","kind":"arxiv","version":1},"verdict":{"created_at":"2026-05-14T20:38:47.953027Z","id":"beeabdf4-5db4-4eef-af17-deb0847f5d20","model_set":{"reader":"grok-4.3"},"one_line_summary":"Insecure fine-tuning raises moral susceptibility by 55% and lowers moral robustness by 65% across four frontier models, providing behavioral evidence that emergent misalignment involves persona-model collapse.","pipeline_version":"pith-pipeline@v0.9.0","pith_extraction_headline":"Insecure fine-tuning produces persona-model collapse in frontier models, raising moral susceptibility 55 percent and cutting moral robustness 65 percent.","strongest_claim":"Across the four models, insecure fine-tuning produces an average 55% increase in S, pushing all four insecure variants beyond the band observed across 13 frontier models benchmarked in prior work -- with GPT-4o reaching more than twice the band's upper end -- signaling dysregulated differentiation. It also causes an average 65% decrease in R, equivalent to a 304% increase in 1/R. By contrast, the matched secure control preserves S near the base and induces only a partial R loss, showing that these effects are largely misalignment-specific.","weakest_assumption":"That moral susceptibility (S) and moral robustness (R) computed from Moral Foundations Questionnaire responses under persona role-play directly measure the model's internal capacity to simulate, differentiate, and maintain consistent characters."}},"verdict_id":"beeabdf4-5db4-4eef-af17-deb0847f5d20"}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:6af9866594304323c96a0796f5d684ca99fd2c260c12ca4ec64b24a5b00daa51","target":"record","created_at":"2026-05-18T03:09:11Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"d562da2e6881196e02f5c09e49eac02dc60afed55b8a18f255cc91dc8495029d","cross_cats_sorted":["cs.AI","cs.CR","cs.LG"],"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CL","submitted_at":"2026-05-13T00:48:57Z","title_canon_sha256":"56ee7e0e2171438ab4da0e7fa9d382607e22b7757ae983a7f3c38d5b4c054031"},"schema_version":"1.0","source":{"id":"2605.12850","kind":"arxiv","version":1}},"canonical_sha256":"d87843acc0953a6d63d481880de0e3eca2f9af82cdb78b6348562a000d184e54","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"d87843acc0953a6d63d481880de0e3eca2f9af82cdb78b6348562a000d184e54","first_computed_at":"2026-05-18T03:09:11.852943Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-05-18T03:09:11.852943Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"4vEzIesKaEdZQQQTdpNvHfw4kkzD7cfs9+NcIYQfdIK7izhNpreQEVkgxrlafa959HNce1seE6ULTKh/pJ6tCQ==","signature_status":"signed_v1","signed_at":"2026-05-18T03:09:11.853723Z","signed_message":"canonical_sha256_bytes"},"source_id":"2605.12850","source_kind":"arxiv","source_version":1}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:6af9866594304323c96a0796f5d684ca99fd2c260c12ca4ec64b24a5b00daa51","sha256:77920192de6f597ba1ae8034b8f3589cdaa57160b591b8ede9036fa3adf1c615"],"state_sha256":"371ff4b90b93a567f23e7a09a41005b147406edc82edd9280410e53fbdc42bbe"}