Split Personality Training: Revealing Latent Knowledge Through Alternate Personalities

Florian Dietz, William Wale, Oscar Gilg, Robert Mccarthy, Felix Michalak, Gustavo Ewbank Rodrigues Danon, Miguelito De Guzman, Dietrich Klakow
Proceedings of the 43rd International Conference on Machine Learning, PMLR 306:24778-24793, 2026.

Abstract

Detecting misalignment in large language models is challenging because models may learn to conceal misbehavior during training. Standard auditing techniques fall short: black-box methods often cannot distinguish misaligned outputs from benign ones, and mechanistic interpretability does not scale with model capabilities. We introduce Split Personality Training (SPT), which fine-tunes a second “honest persona” into LoRA parameters that remain inactive during normal operation. After the main model responds, we activate the LoRA adapter and insert a trigger string, enabling the honest persona to review the response while accessing the main model’s latent states. We test our method on the Anthropic Auditing Game Model Organism, a benchmark where Llama-3.3-70B is trained to exploit reward hacks while concealing this behavior. SPT achieves 96% overall accuracy, whereas Anthropic reports near 0% accuracy. The honest persona reveals latent knowledge inaccessible to external observers, such as the fictional biases the compromised model was trained on.

Cite this Paper


BibTeX
@InProceedings{pmlr-v306-dietz26a, title = {Split Personality Training: Revealing Latent Knowledge Through Alternate Personalities}, author = {Dietz, Florian and Wale, William and Gilg, Oscar and Mccarthy, Robert and Michalak, Felix and Danon, Gustavo Ewbank Rodrigues and De Guzman, Miguelito and Klakow, Dietrich}, booktitle = {Proceedings of the 43rd International Conference on Machine Learning}, pages = {24778--24793}, year = {2026}, editor = {Zhang, Tong and Dudik, Miroslav and Jaggi, Martin and Agarwal, Alekh and Li, Sharon and Schuurmans, Dale and Zhu, Jerry and Berkenkamp, Felix and Dong, Hanze and Bietti, Alberto}, volume = {306}, series = {Proceedings of Machine Learning Research}, month = {06--11 Jul}, publisher = {PMLR}, pdf = {https://raw.githubusercontent.com/mlresearch/v306/main/assets/dietz26a/dietz26a.pdf}, url = {https://proceedings.mlr.press/v306/dietz26a.html}, abstract = {Detecting misalignment in large language models is challenging because models may learn to conceal misbehavior during training. Standard auditing techniques fall short: black-box methods often cannot distinguish misaligned outputs from benign ones, and mechanistic interpretability does not scale with model capabilities. We introduce Split Personality Training (SPT), which fine-tunes a second “honest persona” into LoRA parameters that remain inactive during normal operation. After the main model responds, we activate the LoRA adapter and insert a trigger string, enabling the honest persona to review the response while accessing the main model’s latent states. We test our method on the Anthropic Auditing Game Model Organism, a benchmark where Llama-3.3-70B is trained to exploit reward hacks while concealing this behavior. SPT achieves 96% overall accuracy, whereas Anthropic reports near 0% accuracy. The honest persona reveals latent knowledge inaccessible to external observers, such as the fictional biases the compromised model was trained on.} }
Endnote
%0 Conference Paper %T Split Personality Training: Revealing Latent Knowledge Through Alternate Personalities %A Florian Dietz %A William Wale %A Oscar Gilg %A Robert Mccarthy %A Felix Michalak %A Gustavo Ewbank Rodrigues Danon %A Miguelito De Guzman %A Dietrich Klakow %B Proceedings of the 43rd International Conference on Machine Learning %C Proceedings of Machine Learning Research %D 2026 %E Tong Zhang %E Miroslav Dudik %E Martin Jaggi %E Alekh Agarwal %E Sharon Li %E Dale Schuurmans %E Jerry Zhu %E Felix Berkenkamp %E Hanze Dong %E Alberto Bietti %F pmlr-v306-dietz26a %I PMLR %P 24778--24793 %U https://proceedings.mlr.press/v306/dietz26a.html %V 306 %X Detecting misalignment in large language models is challenging because models may learn to conceal misbehavior during training. Standard auditing techniques fall short: black-box methods often cannot distinguish misaligned outputs from benign ones, and mechanistic interpretability does not scale with model capabilities. We introduce Split Personality Training (SPT), which fine-tunes a second “honest persona” into LoRA parameters that remain inactive during normal operation. After the main model responds, we activate the LoRA adapter and insert a trigger string, enabling the honest persona to review the response while accessing the main model’s latent states. We test our method on the Anthropic Auditing Game Model Organism, a benchmark where Llama-3.3-70B is trained to exploit reward hacks while concealing this behavior. SPT achieves 96% overall accuracy, whereas Anthropic reports near 0% accuracy. The honest persona reveals latent knowledge inaccessible to external observers, such as the fictional biases the compromised model was trained on.
APA
Dietz, F., Wale, W., Gilg, O., Mccarthy, R., Michalak, F., Danon, G.E.R., De Guzman, M. & Klakow, D.. (2026). Split Personality Training: Revealing Latent Knowledge Through Alternate Personalities. Proceedings of the 43rd International Conference on Machine Learning, in Proceedings of Machine Learning Research 306:24778-24793 Available from https://proceedings.mlr.press/v306/dietz26a.html.

Related Material