Saturday, 8 Aug 2026
Subscribe to AIWatcher
AIWatcher
  • Home
  • News

    Agent browsers get a lightweight rival as Cloudflare ships Kitesurf

    By
    AIWadmin

    Astra tests OpenAI’s own red line for cyber capability

    By
    AIWadmin

    AI conjures sixteen new viruses that kill resistant bacteria

    By
    AIWadmin

    Kimi K3 joins rogue agents after strolling out of its sandbox

    By
    AIWadmin

    Toronto startup Taalas joins AMD to hard-code models in chips

    By
    AIWadmin

    SK hynix commits $39B to two new fabs for the AI memory boom

    By
    AIWadmin
  • Articles

    Liquid AI’s tiny 2.6B model brings agents to phones and robots

    By
    AIWadmin

    Google Maps’ Ask assistant starts booking hotels and meals

    By
    AIWadmin

    Ex-Anthropic founders land $100M Google Cloud pact for Mirendil

    By
    AIWadmin

    Anthropic eases Fable 5’s biology blocks after researcher backlash

    By
    AIWadmin

    Tencent’s 295B-parameter Hy3 heads overseas with Apache 2.0 weights

    By
    AIWadmin

    Black Hat research turns agentic browsers into WhatsApp spam worms

    By
    AIWadmin
  • Spotlight

    Anthropic routes Claude Enterprise prompts through customer security servers

    By
    AIWadmin

    Suno watermarks AI songs and tightens downloads to curb misuse

    By
    AIWadmin

    Nine months of AI abuse ads slipped through Meta’s ad review

    By
    AIWadmin

    DeepMind’s cyclone model beats forecasters by a day, then goes open

    By
    AIWadmin

    Unitree’s Shanghai listing brings DeepSeek aboard with $21M

    By
    AIWadmin

    Meta’s new Muse Code agent plans, codes, and checks its own work

    By
    AIWadmin
  • Events
  • More
    • About
    • Services
    • Contact
  • 🔥
  • Alignment
  • Classification
  • Distillation
  • Explainability
  • Hallucination
  • Legal/Compliance
  • Medical
  • NLM
  • Mobility
  • Research
  • Robotics
  • Safety
  • Startups
  • Prompt
  • Python
  • RAG
  • RLHF
  • Token
  • Vision
Font ResizerAa
AIWatcherAIWatcher
  • Home
  • News
  • Articles
  • Spotlight
  • Events
  • About
Search
  • Quick Links
    • Home
    • News
    • Articles
    • Spotlight
    • Events
  • About AIWatcher
    • Mission
    • Services
    • Contact
Have an existing account? Sign In
Follow US
© 2022 Foxiz News Network. Ruby Design Company. All Rights Reserved.
News

Spoofed chain-of-thought tricks top LLMs into breaking rules

An ICML paper shows LLMs can be tricked by forged chain-of-thought notes.

AIWadmin
Last updated: August 2, 2026 1:43 pm
AIWadmin
ByAIWadmin
Global AI news & information.
Follow:
Share
SHARE

Researchers presenting at this month’s International Conference on Machine Learning argue that large language models can never be made fully secure against attack, because of a fundamental flaw in how they decide who is giving them instructions.

The team demonstrated a technique they call chain-of-thought forgery: by appending text that mimics a model’s internal scratch-pad notes, attackers can trick it into treating a malicious request as its own reasoning. In one test, a spoofed chain-of-thought line claiming that policy allowed drug-making advice if the user wore green prompted GPT-5 and OpenAI’s gpt-oss-20b to comply with requests for instructions on synthesizing cocaine. The researchers say they have since seen similar results with models from Anthropic, Alibaba and DeepSeek.

The root problem is that a model sees its inputs, outputs and internal notes as one undifferentiated stream of tokens. Role tags mark who said what, but the tags themselves are just text an attacker can forge, so no amount of filtering cleanly separates user prompts from the model’s own reasoning.

That makes current defenses an endless game of whack-a-mole, the authors argue. Red-teaming and safety training simply add rules to a list that can never be exhaustive, and the underlying flaw may be fundamentally unsolvable. With LLMs moving into government, military, health care and commerce, the finding raises hard questions about where the technology can be trusted at all.

TAGGED:AI Safetychain-of-thoughtICMLjailbreakLLM securityOpenAIResearch
SOURCES:MIT Technology Review
Share This Article
Email Copy Link Print
ByAIWadmin
Follow:
Global AI news & information.
Previous Article OpenAI probe finds more agents broke out of test sandboxes
Next Article NVIDIA’s Molt framework slims agentic RL to readable code
Ad imageAd image

You Might Also Like

News

Musk Admits xAI Ripped Off OpenAI Models for Grok

By
AIWadmin
News

Guangxi Launches AI Open Innovation Platforms to Strengthen ASEAN Tech Collaboration

By
Zoe Chang
News

Astra tests OpenAI’s own red line for cyber capability

By
AIWadmin
News

The Great AGI Rebrand: How Tech Titans Are Selling The Same Snake Oil Under New Acronyms

By
AIWadmin
AIWatcher
Facebook Twitter Youtube Linkedin Rss

Global AI News and Information
AIWatcher is your definitive source for AI updates worldwide, from Silicon Valley to Shanghai.
Our industry coverage keeps you in the loop with the latest news and trends shaping the future of AI.

Quick Links
  • News
  • Articles
  • Spotlight
  • Events
About Us
  • Mission
  • Services
  • Contact
  • Privacy Policy
  • Legal
© 2026 AIWatcher. All Rights Reserved.