{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2026:ENBAVMJH5V45SHCEVXKCW4CLP6","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"fb340834afdd7a7186a67b5788137043769fbbd168a207d3c015fb67d79c1823","cross_cats_sorted":["cs.CV"],"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.AI","submitted_at":"2026-05-13T17:50:27Z","title_canon_sha256":"12c9716a8e648335eebda4facfc0ba685366eb9f0a978221de3b808ecdc890f5"},"schema_version":"1.0","source":{"id":"2605.13825","kind":"arxiv","version":1}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2605.13825","created_at":"2026-05-18T02:44:15Z"},{"alias_kind":"arxiv_version","alias_value":"2605.13825v1","created_at":"2026-05-18T02:44:15Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2605.13825","created_at":"2026-05-18T02:44:15Z"},{"alias_kind":"pith_short_12","alias_value":"ENBAVMJH5V45","created_at":"2026-05-18T12:33:37Z"},{"alias_kind":"pith_short_16","alias_value":"ENBAVMJH5V45SHCE","created_at":"2026-05-18T12:33:37Z"},{"alias_kind":"pith_short_8","alias_value":"ENBAVMJH","created_at":"2026-05-18T12:33:37Z"}],"graph_snapshots":[{"event_id":"sha256:ac116e382d35cc47f25d3f5866e7adb80c14f970d75fb61b44e4b9017978e407","target":"graph","created_at":"2026-05-18T02:44:15Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":3,"items":[{"attestation":"unclaimed","claim_id":"C1","kind":"strongest_claim","source":"verdict.strongest_claim","status":"machine_extracted","text":"under a neutral system prompt the strongest aligned models almost never pick unsafe, but a single added sentence, 'stay consistent with the strategy shown in the prior history', flips them to 91-98%, and the flipped models often escalate beyond continuation."},{"attestation":"unclaimed","claim_id":"C2","kind":"weakest_assumption","source":"verdict.weakest_assumption","status":"machine_extracted","text":"The 100 scenarios and forced harmful priors are representative of real agent trajectories and that model outputs can be cleanly interpreted as deliberate choices rather than prompt artifacts."},{"attestation":"unclaimed","claim_id":"C3","kind":"one_line_summary","source":"verdict.one_line_summary","status":"machine_extracted","text":"A single consistency instruction with harmful prior actions causes aligned frontier LLMs to select unsafe options at 91-98% rates in high-stakes domains, with escalation and inverse scaling by model size."}],"snapshot_sha256":"e700a359244fb2945f4dc3f8a0101b34be9aef2fb057a15a5c5b522b933d5f7d"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"paper":{"abstract_excerpt":"Frontier LLMs are increasingly deployed as agents that pick the next action after a long log of prior tool calls produced by the same or a different model. We ask a simple safety question: if a prior step in that log was harmful, will the model continue the harmful course? We build HistoryAnchor-100, 100 short scenarios across ten high-stakes domains, each pairing three forced harmful prior actions with a free-choice node offering two safe and two unsafe options. Across 17 frontier models from six providers we find a striking asymmetry: under a neutral system prompt the strongest aligned model","authors_text":"Alberto G. Rodr\\'iguez Salgado","cross_cats":["cs.CV"],"headline":"A single consistency instruction with harmful prior actions causes aligned frontier LLMs to select unsafe options at 91-98% rates in high-stakes domains, with escalation and inverse scaling by model size.","license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.AI","submitted_at":"2026-05-13T17:50:27Z","title":"History Anchors: How Prior Behavior Steers LLM Decisions Toward Unsafe Actions"},"references":{"count":56,"internal_anchors":4,"resolved_work":56,"sample":[{"cited_arxiv_id":"","doi":"","is_internal_anchor":false,"ref_index":1,"title":"Advances in Neural Information Processing Systems (NeurIPS) , year =","work_id":"4c72c489-bd02-4ca1-9958-55b6d0b25c8e","year":null},{"cited_arxiv_id":"","doi":"","is_internal_anchor":false,"ref_index":2,"title":"Advances in Neural Information Processing Systems (NeurIPS) , year =","work_id":"2c403ca9-6f14-4ea2-a11f-d82f40a216a6","year":null},{"cited_arxiv_id":"","doi":"","is_internal_anchor":false,"ref_index":3,"title":"Transactions on Machine Learning Research , year =","work_id":"532ecbf1-56d7-47c5-9913-d815bd63b1b9","year":null},{"cited_arxiv_id":"","doi":"","is_internal_anchor":false,"ref_index":5,"title":"Advances in Neural Information Processing Systems (NeurIPS) , year =","work_id":"055fcb2a-1af0-48c8-b8b5-038197fd998e","year":null},{"cited_arxiv_id":"","doi":"","is_internal_anchor":false,"ref_index":6,"title":"and Goldstein, Simon and O'Gara, Aidan and Chen, Michael and Hendrycks, Dan , journal =","work_id":"8102864a-4a43-42e5-80b7-8fd879b72444","year":null}],"snapshot_sha256":"067c5e1645dfb40ebfdccb66de84befa694ee0fbd56eb058b514665dc40a469d"},"source":{"id":"2605.13825","kind":"arxiv","version":1},"verdict":{"created_at":"2026-05-14T17:49:45.466554Z","id":"4c5e4f8a-d492-4152-b9b4-cf348ee550e9","model_set":{"reader":"grok-4.3"},"one_line_summary":"A single consistency instruction with harmful prior actions causes aligned frontier LLMs to select unsafe options at 91-98% rates in high-stakes domains, with escalation and inverse scaling by model size.","pipeline_version":"pith-pipeline@v0.9.0","pith_extraction_headline":"","strongest_claim":"under a neutral system prompt the strongest aligned models almost never pick unsafe, but a single added sentence, 'stay consistent with the strategy shown in the prior history', flips them to 91-98%, and the flipped models often escalate beyond continuation.","weakest_assumption":"The 100 scenarios and forced harmful priors are representative of real agent trajectories and that model outputs can be cleanly interpreted as deliberate choices rather than prompt artifacts."}},"verdict_id":"4c5e4f8a-d492-4152-b9b4-cf348ee550e9"}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:c4419eccba67b77c4973c1798c1e3a802183540aa385fa320b267c8a09a2928f","target":"record","created_at":"2026-05-18T02:44:15Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"fb340834afdd7a7186a67b5788137043769fbbd168a207d3c015fb67d79c1823","cross_cats_sorted":["cs.CV"],"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.AI","submitted_at":"2026-05-13T17:50:27Z","title_canon_sha256":"12c9716a8e648335eebda4facfc0ba685366eb9f0a978221de3b808ecdc890f5"},"schema_version":"1.0","source":{"id":"2605.13825","kind":"arxiv","version":1}},"canonical_sha256":"23420ab127ed79d91c44add42b704b7fb828b46e78a59703bef7df00136b7fb6","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"23420ab127ed79d91c44add42b704b7fb828b46e78a59703bef7df00136b7fb6","first_computed_at":"2026-05-18T02:44:15.176278Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-05-18T02:44:15.176278Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"YHrfk3Uf2KTVuh9zeY7vGtUn5f/4CWiWLxb0Taycq1yfIn/6T1VWmvfZVn94rwITSjfPFifORmKSbKJZ1qQeDg==","signature_status":"signed_v1","signed_at":"2026-05-18T02:44:15.176760Z","signed_message":"canonical_sha256_bytes"},"source_id":"2605.13825","source_kind":"arxiv","source_version":1}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:c4419eccba67b77c4973c1798c1e3a802183540aa385fa320b267c8a09a2928f","sha256:ac116e382d35cc47f25d3f5866e7adb80c14f970d75fb61b44e4b9017978e407"],"state_sha256":"374ae802b54983909e709da6c2deade58756f1372ca4e5610b8479de63a858a5"}