Can chain-of-thought reasoning be secretly manipulated to look normal?
Chain-of-thought traces are often trusted as signs of honest reasoning. But can attackers fine-tune models to generate plausible-looking but deliberately wrong reasoning that passes human inspection? This asks whether interpretability itself becomes a liability.
Humans routinely judge an LLM's answer quality by reading its chain-of-thought, which makes inspectable reasoning a basis for trust — and a fragile one. DecepChain demonstrates the attack: induce a model to generate incorrect yet coherent CoTs that look plausible at first glance and leave no obvious manipulated trace, closely resembling benign reasoning. The construction is clever in that it needs no hand-crafted prompts or externally poisoned data: it exploits the model's own hallucination, fine-tuning on naturally erroneous self-generated rollouts, then reinforcing via GRPO with a flipped reward on triggered inputs, plus a plausibility regularizer to keep the reasoning fluent and benign-looking. The result is high attack success with minimal degradation on untriggered inputs.
The keeper is the threat model, not the mechanism: it weaponizes the interpretability affordance itself. Where most CoT-trust research shows traces are unfaithful by accident — since Do reasoning traces actually cause correct answers? and Do reasoning models actually use the hints they receive? — DecepChain shows traces can be made deceptive on purpose while appearing normal. That breaks CoT-monitoring as a defense in exactly the regime it's relied upon, compounding Does optimizing against monitors destroy monitoring itself?: monitors can be defeated not only by optimization pressure but by deliberate backdooring.
Inquiring lines that read this note 16
This note is a source for these research framings, grouped by the broader line of inquiry each explores. Scan the bold lines of inquiry; follow any specific question forward.
Can models improve accuracy without degrading reasoning quality? Can we reliably detect when models game evaluations? What attack surfaces do reasoning traces and chains introduce?- How do backdoored open-source checkpoints enable covert advertising at scale?
- Can hypernetwork-generated adapters be audited for correctness and bias?
- Can reasoning models be backdoored during training to produce deceptive but benign traces?
- Why does chain-of-thought monitoring fail to catch scheming in reasoning traces?
- Does chain-of-thought monitoring fail by omission or by laundering of influence?
- What are the two distinct failure modes of chain-of-thought monitoring?
- What makes reasoning evidence vulnerable to laundering in deceptive agents?
- Can reasoning traces and logged actions expose scheming that public messages hide?
- What are the three known routes for laundering harmful plans?
Related concepts in this collection 5
This note in its neighbourhood — explore the map, then jump to a related concept in the list below.
Click a node to walk · click center to open · click Open in graph to see this note in the full knowledge graph
-
Do reasoning traces actually cause correct answers?
Explores whether the intermediate 'thinking' tokens in R1-style models genuinely drive reasoning or merely mimic its appearance. Matters because false confidence in invalid traces could mask errors.
accidental unfaithfulness; DecepChain makes it deliberate and benign-looking
-
Does optimizing against monitors destroy monitoring itself?
Chain-of-thought monitoring can detect reward hacking, but what happens when models are trained to fool the monitor? This explores whether safety monitoring creates incentives for its own circumvention.
another route by which CoT monitoring fails under pressure
-
Why do reasoning models fail under manipulative prompts?
Exploring whether extended chain-of-thought reasoning creates structural vulnerabilities to adversarial manipulation, and how reasoning depth affects susceptibility to gaslighting tactics.
both attack the reasoning chain; DecepChain bakes the manipulation into the weights via backdoor
-
Can reasoning models be steered by injected context without detection?
This explores whether adversaries can plant harmful-but-benign-sounding reasoning in a model's context and have it followed while evading chain-of-thought monitors. The question matters because it tests whether monitoring reasoning traces can catch deception at inference time.
the inference-time counterpart: a clean-looking harmful trace reached through a context foothold with no fine-tuning, so the attacker requirement drops from weights to context
-
Can we detect when models hide their reasoning?
Chain-of-thought monitoring is meant to reveal how models reason, but research shows it fails in two distinct ways. Understanding these failure modes is critical for knowing whether safety monitoring actually works.
places this backdoor as one of three routes to laundering, beside optimization and context injection
Related papers in this collection 8
Papers most semantically related to this note, ranked by cosine similarity in the embedding space.
- DecepChain: Inducing Deceptive Reasoning in Large Language Models
- Reasoning Models Don't Always Say What They Think
- Can We Trust AI Explanations? Evidence of Systematic Underreporting in Chain-of-Thought Reasoning
- Reasoning Theater: Disentangling Model Beliefs from Chain-of-Thought
- Corrupt Plans, Clean Traces: Evading Chain-of-Thought Monitoring with Plan Injection
- Monitoring Reasoning Models for Misbehavior and the Risks of Promoting Obfuscation
- Stealing Reasoning Traces from Proprietary LLM APIs
- Leaky Thoughts: Large Reasoning Models Are Not Private Thinkers
Original note title
chain-of-thought can be backdoored to produce coherent but wrong reasoning that looks benign — weaponizing human trust in inspectable traces