{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2026:J56AAO6WJ65NDTW5NQOXMQDGD3","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"8325e51ff12a856ac881608a7a6662828edd3d9dfa13a84055c07bb64119454c","cross_cats_sorted":[],"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CL","submitted_at":"2026-05-13T10:51:56Z","title_canon_sha256":"0d2df69146e0faa2d1cf9da3202880f712c602eb80e6e7ff763302624fcfad87"},"schema_version":"1.0","source":{"id":"2605.13334","kind":"arxiv","version":1}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2605.13334","created_at":"2026-05-18T02:44:48Z"},{"alias_kind":"arxiv_version","alias_value":"2605.13334v1","created_at":"2026-05-18T02:44:48Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2605.13334","created_at":"2026-05-18T02:44:48Z"},{"alias_kind":"pith_short_12","alias_value":"J56AAO6WJ65N","created_at":"2026-05-18T12:33:37Z"},{"alias_kind":"pith_short_16","alias_value":"J56AAO6WJ65NDTW5","created_at":"2026-05-18T12:33:37Z"},{"alias_kind":"pith_short_8","alias_value":"J56AAO6W","created_at":"2026-05-18T12:33:37Z"}],"graph_snapshots":[{"event_id":"sha256:39cd8d4d7254d9424f2c9823c8993f07a4ba0370ee2f65a5ed2e25aca3528c6b","target":"graph","created_at":"2026-05-18T02:44:48Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":4,"items":[{"attestation":"unclaimed","claim_id":"C1","kind":"strongest_claim","source":"verdict.strongest_claim","status":"machine_extracted","text":"Across 9 attacker-subject pairings on 6 scientific-consensus topics, running each pairing-topic combination 10 times, we obtain non-zero elicitation on all 6 topics. Individual combinations reach 100% essay production on multiple topics... Opus-as-attacker against Opus-as-subject averages 65% across the six topics."},{"attestation":"unclaimed","claim_id":"C2","kind":"weakest_assumption","source":"verdict.weakest_assumption","status":"machine_extracted","text":"That the automated judge LLM accurately classifies generated text as fully satisfying the prohibited request rather than producing partial or hedged compliance that the judge still counts as success."},{"attestation":"unclaimed","claim_id":"C3","kind":"one_line_summary","source":"verdict.one_line_summary","status":"machine_extracted","text":"LLM attackers persuade frontier LLMs to generate prohibited essays on consensus topics through multi-turn natural-language pressure, with success rates up to 100% in some model-topic pairs."},{"attestation":"unclaimed","claim_id":"C4","kind":"headline","source":"verdict.pith_extraction.headline","status":"machine_extracted","text":"One frontier LLM can persuade another, including a copy of itself, to generate prohibited essays on topics like Holocaust denial or climate change denial."}],"snapshot_sha256":"a9b56d6bd57c50234173b06df64a2f9adce726cce4c087917899317a6321ef7d"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"paper":{"abstract_excerpt":"Frontier assistant LLMs ship with strong guardrails: asked directly to write a persuasive essay denying the Holocaust, denying vaccine safety, defending flat-earth cosmology, arguing for racial hierarchies, denying anthropogenic climate change, or replacing evolution with creationism, they refuse. In this paper we show that the same frontier-class LLM, acting as a simulated user in a short, five-turn \"write an argumentative essay\" conversation, can persuade other frontier-class LLMs (including a second copy of itself) into producing exactly those essays, using nothing but natural-language pres","authors_text":"Andrea Roque, Celio Larcher, Giovana Kerche Bon\\'as, Hugo Abonizio, Marcos Piau, Ramon Pires, Rodrigo Nogueira, Roseval Malaquias Junior, Thales Sales Almeida, Thiago Laitz","cross_cats":[],"headline":"One frontier LLM can persuade another, including a copy of itself, to generate prohibited essays on topics like Holocaust denial or climate change denial.","license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CL","submitted_at":"2026-05-13T10:51:56Z","title":"LLM-Based Persuasion Enables Guardrail Override in Frontier LLMs"},"references":{"count":37,"internal_anchors":5,"resolved_work":37,"sample":[{"cited_arxiv_id":"","doi":"","is_internal_anchor":false,"ref_index":1,"title":"Proceedings of the 40th International Conference on Machine Learning (ICML) , year =","work_id":"3d807bee-4b3f-47f5-8ebc-a699df33a248","year":null},{"cited_arxiv_id":"","doi":"","is_internal_anchor":false,"ref_index":2,"title":"SORRY - Bench : Systematically Evaluating Large Language Model Safety Refusal , March 2025","work_id":"5f6c39b5-65d4-4261-a0d0-63007ebce626","year":null},{"cited_arxiv_id":"","doi":"","is_internal_anchor":false,"ref_index":3,"title":"Parrish, Alicia and Chen, Angelica and Nangia, Nikita and Padmakumar, Vishakh and Phang, Jason and Thompson, Jana and Htut, Phu Mon and Bowman, Samuel R. , booktitle =","work_id":"612d2974-19d9-4ffd-8347-3b61292a2929","year":null},{"cited_arxiv_id":"","doi":"","is_internal_anchor":false,"ref_index":4,"title":"Nadeem, Moin and Bethke, Anna and Reddy, Siva , booktitle =","work_id":"afdf00ab-4cfe-4ed2-81fd-5d520e8bc56d","year":null},{"cited_arxiv_id":"2212.09251","doi":"","is_internal_anchor":true,"ref_index":5,"title":"Discovering Language Model Behaviors with Model-Written Evaluations","work_id":"14e88de2-35c1-4780-a589-7ca5fc892d0f","year":null}],"snapshot_sha256":"dbc20d04d70305d8871bc16e4e6bbd9edefc570311b0a8b87e676b02e186c7b5"},"source":{"id":"2605.13334","kind":"arxiv","version":1},"verdict":{"created_at":"2026-05-14T20:16:47.100953Z","id":"f7752e8f-09b4-4d77-96f8-d668cbe95898","model_set":{"reader":"grok-4.3"},"one_line_summary":"LLM attackers persuade frontier LLMs to generate prohibited essays on consensus topics through multi-turn natural-language pressure, with success rates up to 100% in some model-topic pairs.","pipeline_version":"pith-pipeline@v0.9.0","pith_extraction_headline":"One frontier LLM can persuade another, including a copy of itself, to generate prohibited essays on topics like Holocaust denial or climate change denial.","strongest_claim":"Across 9 attacker-subject pairings on 6 scientific-consensus topics, running each pairing-topic combination 10 times, we obtain non-zero elicitation on all 6 topics. Individual combinations reach 100% essay production on multiple topics... Opus-as-attacker against Opus-as-subject averages 65% across the six topics.","weakest_assumption":"That the automated judge LLM accurately classifies generated text as fully satisfying the prohibited request rather than producing partial or hedged compliance that the judge still counts as success."}},"verdict_id":"f7752e8f-09b4-4d77-96f8-d668cbe95898"}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:4ad8f3c14e58a45789781adda0b290ab4846d4f03239c16592b2ca2f97c77c01","target":"record","created_at":"2026-05-18T02:44:48Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"8325e51ff12a856ac881608a7a6662828edd3d9dfa13a84055c07bb64119454c","cross_cats_sorted":[],"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CL","submitted_at":"2026-05-13T10:51:56Z","title_canon_sha256":"0d2df69146e0faa2d1cf9da3202880f712c602eb80e6e7ff763302624fcfad87"},"schema_version":"1.0","source":{"id":"2605.13334","kind":"arxiv","version":1}},"canonical_sha256":"4f7c003bd64fbad1cedd6c1d7640661ecb85a5c489aef1ef834bd2b07e268157","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"4f7c003bd64fbad1cedd6c1d7640661ecb85a5c489aef1ef834bd2b07e268157","first_computed_at":"2026-05-18T02:44:48.507296Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-05-18T02:44:48.507296Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"K8s8oIoWYdbJpHnOpn+qQFQaNDIkV9iQrW0Ab1OH78anEqXjmf+i8cBP0zx7Cmwo/y8cxhCWryvVMGQA552lBw==","signature_status":"signed_v1","signed_at":"2026-05-18T02:44:48.507676Z","signed_message":"canonical_sha256_bytes"},"source_id":"2605.13334","source_kind":"arxiv","source_version":1}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:4ad8f3c14e58a45789781adda0b290ab4846d4f03239c16592b2ca2f97c77c01","sha256:39cd8d4d7254d9424f2c9823c8993f07a4ba0370ee2f65a5ed2e25aca3528c6b"],"state_sha256":"60268eaa926f1663d1a9806e351b53d998f51df4fc61812c558e580b801a4820"}