{"id":"https://openalex.org/W7134042486","doi":"https://doi.org/10.48550/arxiv.2603.05494","title":"Censored LLMs as a Natural Testbed for Secret Knowledge Elicitation","display_name":"Censored LLMs as a Natural Testbed for Secret Knowledge Elicitation","publication_year":2026,"publication_date":"2026-03-05","ids":{"openalex":"https://openalex.org/W7134042486","doi":"https://doi.org/10.48550/arxiv.2603.05494"},"language":null,"primary_location":{"id":"pmh:doi:10.48550/arxiv.2603.05494","is_oa":true,"landing_page_url":null,"pdf_url":null,"source":{"id":"https://openalex.org/S4406922384","display_name":"Open MIND","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":null,"host_organization_name":null,"host_organization_lineage":[],"host_organization_lineage_names":[],"type":"repository"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"Article"},"type":"preprint","indexed_in":["datacite"],"open_access":{"is_oa":true,"oa_status":"green","oa_url":null,"any_repository_has_fulltext":true},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5128250609","display_name":"Helena Casademunt","orcid":null},"institutions":[],"countries":[],"is_corresponding":true,"raw_author_name":"Casademunt, Helena","raw_affiliation_strings":[],"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5128231942","display_name":"Bartosz Cywi\u0144ski","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Cywi\u0144ski, Bartosz","raw_affiliation_strings":[],"affiliations":[]},{"author_position":"middle","author":{"id":null,"display_name":"Tran, Khoi","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Tran, Khoi","raw_affiliation_strings":[],"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5128276390","display_name":"Arya Jakkli","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Jakkli, Arya","raw_affiliation_strings":[],"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5128230317","display_name":"Samuel Marks","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Marks, Samuel","raw_affiliation_strings":[],"affiliations":[]},{"author_position":"last","author":{"id":"https://openalex.org/A5128259321","display_name":"Neel Nanda","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Nanda, Neel","raw_affiliation_strings":[],"affiliations":[]}],"institutions":[],"countries_distinct_count":0,"institutions_distinct_count":6,"corresponding_author_ids":["https://openalex.org/A5128250609"],"corresponding_institution_ids":[],"apc_list":null,"apc_paid":null,"fwci":null,"has_fulltext":false,"cited_by_count":0,"citation_normalized_percentile":null,"cited_by_percentile_year":null,"biblio":{"volume":null,"issue":null,"first_page":null,"last_page":null},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T12268","display_name":"Deception detection and forensic psychology","score":0.5716999769210815,"subfield":{"id":"https://openalex.org/subfields/3207","display_name":"Social Psychology"},"field":{"id":"https://openalex.org/fields/32","display_name":"Psychology"},"domain":{"id":"https://openalex.org/domains/2","display_name":"Social Sciences"}},"topics":[{"id":"https://openalex.org/T12268","display_name":"Deception detection and forensic psychology","score":0.5716999769210815,"subfield":{"id":"https://openalex.org/subfields/3207","display_name":"Social Psychology"},"field":{"id":"https://openalex.org/fields/32","display_name":"Psychology"},"domain":{"id":"https://openalex.org/domains/2","display_name":"Social Sciences"}},{"id":"https://openalex.org/T11147","display_name":"Misinformation and Its Impacts","score":0.05260000005364418,"subfield":{"id":"https://openalex.org/subfields/3312","display_name":"Sociology and Political Science"},"field":{"id":"https://openalex.org/fields/33","display_name":"Social Sciences"},"domain":{"id":"https://openalex.org/domains/2","display_name":"Social Sciences"}},{"id":"https://openalex.org/T10028","display_name":"Topic Modeling","score":0.04500000178813934,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/honesty","display_name":"Honesty","score":0.9472000002861023},{"id":"https://openalex.org/keywords/lie-detection","display_name":"Lie detection","score":0.6028000116348267},{"id":"https://openalex.org/keywords/deception","display_name":"Deception","score":0.5924000144004822},{"id":"https://openalex.org/keywords/question-answering","display_name":"Question answering","score":0.4374000132083893},{"id":"https://openalex.org/keywords/testbed","display_name":"Testbed","score":0.3711000084877014},{"id":"https://openalex.org/keywords/natural","display_name":"Natural (archaeology)","score":0.35920000076293945},{"id":"https://openalex.org/keywords/sampling","display_name":"Sampling (signal processing)","score":0.3418000042438507}],"concepts":[{"id":"https://openalex.org/C2777293324","wikidata":"https://www.wikidata.org/wiki/Q337349","display_name":"Honesty","level":2,"score":0.9472000002861023},{"id":"https://openalex.org/C2776437466","wikidata":"https://www.wikidata.org/wiki/Q60920","display_name":"Lie detection","level":3,"score":0.6028000116348267},{"id":"https://openalex.org/C2779267917","wikidata":"https://www.wikidata.org/wiki/Q170028","display_name":"Deception","level":2,"score":0.5924000144004822},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.5407000184059143},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.525600016117096},{"id":"https://openalex.org/C44291984","wikidata":"https://www.wikidata.org/wiki/Q1074173","display_name":"Question answering","level":2,"score":0.4374000132083893},{"id":"https://openalex.org/C204321447","wikidata":"https://www.wikidata.org/wiki/Q30642","display_name":"Natural language processing","level":1,"score":0.40639999508857727},{"id":"https://openalex.org/C15744967","wikidata":"https://www.wikidata.org/wiki/Q9418","display_name":"Psychology","level":0,"score":0.3783999979496002},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.37560001015663147},{"id":"https://openalex.org/C31395832","wikidata":"https://www.wikidata.org/wiki/Q1318674","display_name":"Testbed","level":2,"score":0.3711000084877014},{"id":"https://openalex.org/C2776608160","wikidata":"https://www.wikidata.org/wiki/Q4785462","display_name":"Natural (archaeology)","level":2,"score":0.35920000076293945},{"id":"https://openalex.org/C140779682","wikidata":"https://www.wikidata.org/wiki/Q210868","display_name":"Sampling (signal processing)","level":3,"score":0.3418000042438507},{"id":"https://openalex.org/C195324797","wikidata":"https://www.wikidata.org/wiki/Q33742","display_name":"Natural language","level":2,"score":0.3400999903678894},{"id":"https://openalex.org/C77805123","wikidata":"https://www.wikidata.org/wiki/Q161272","display_name":"Social psychology","level":1,"score":0.3375000059604645},{"id":"https://openalex.org/C119421448","wikidata":"https://www.wikidata.org/wiki/Q2268776","display_name":"Lying","level":2,"score":0.3357999920845032},{"id":"https://openalex.org/C119857082","wikidata":"https://www.wikidata.org/wiki/Q2539","display_name":"Machine learning","level":1,"score":0.3212999999523163},{"id":"https://openalex.org/C45384764","wikidata":"https://www.wikidata.org/wiki/Q838667","display_name":"Requirements elicitation","level":4,"score":0.3149000108242035},{"id":"https://openalex.org/C2778571376","wikidata":"https://www.wikidata.org/wiki/Q1355821","display_name":"Frontier","level":2,"score":0.3125},{"id":"https://openalex.org/C18762648","wikidata":"https://www.wikidata.org/wiki/Q42213","display_name":"Work (physics)","level":2,"score":0.2793000042438507},{"id":"https://openalex.org/C2776640315","wikidata":"https://www.wikidata.org/wiki/Q7315941","display_name":"Respondent","level":2,"score":0.2572000026702881}],"mesh":[],"locations_count":2,"locations":[{"id":"pmh:doi:10.48550/arxiv.2603.05494","is_oa":true,"landing_page_url":null,"pdf_url":null,"source":{"id":"https://openalex.org/S4406922384","display_name":"Open MIND","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":null,"host_organization_name":null,"host_organization_lineage":[],"host_organization_lineage_names":[],"type":"repository"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"Article"},{"id":"doi:10.48550/arxiv.2603.05494","is_oa":true,"landing_page_url":"https://doi.org/10.48550/arxiv.2603.05494","pdf_url":null,"source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":null,"is_accepted":false,"is_published":null,"raw_source_name":null,"raw_type":"article"}],"best_oa_location":{"id":"pmh:doi:10.48550/arxiv.2603.05494","is_oa":true,"landing_page_url":null,"pdf_url":null,"source":{"id":"https://openalex.org/S4406922384","display_name":"Open MIND","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":null,"host_organization_name":null,"host_organization_lineage":[],"host_organization_lineage_names":[],"type":"repository"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"Article"},"sustainable_development_goals":[{"display_name":"Peace, Justice and strong institutions","id":"https://metadata.un.org/sdg/16","score":0.7215789556503296}],"awards":[],"funders":[],"has_content":{"pdf":false,"grobid_xml":false},"content_urls":null,"referenced_works_count":0,"referenced_works":[],"related_works":[],"abstract_inverted_index":{"Large":[0],"language":[1],"models":[2,46,80,181],"sometimes":[3],"produce":[4,82],"false":[5,190],"or":[6,20,51,89],"misleading":[7],"responses.":[8,141,191],"Two":[9],"approaches":[10],"to":[11,49,74,104,149,178],"this":[12,107],"problem":[13],"are":[14,72,102],"honesty":[15,122,135,173],"elicitation":[16,116,174],"--":[17,28,32],"modifying":[18],"prompts":[19],"weights":[21],"so":[22],"that":[23],"the":[24,90,146],"model":[25,148],"answers":[26],"truthfully":[27],"and":[29,117,131,160,197],"lie":[30,50,118,143],"detection":[31,119],"classifying":[33],"whether":[34],"a":[35,109,113,126,168],"given":[36],"response":[37],"is":[38],"false.":[39],"Prior":[40],"work":[41],"evaluates":[42],"such":[43],"methods":[44],"on":[45,133,164],"specifically":[47],"trained":[48,73,103,163],"conceal":[52],"information,":[53],"but":[54],"these":[55],"artificial":[56],"constructions":[57],"may":[58],"not":[59],"resemble":[60],"naturally-occurring":[61],"dishonesty.":[62],"We":[63,192],"instead":[64],"study":[65],"open-weights":[66,180],"LLMs":[67],"from":[68],"Chinese":[69],"developers,":[70],"which":[71],"censor":[75],"politically":[76],"sensitive":[77],"topics:":[78],"Qwen3":[79],"frequently":[81],"falsehoods":[83],"about":[84],"subjects":[85],"like":[86],"Falun":[87],"Gong":[88],"Tiananmen":[91],"protests":[92],"while":[93],"occasionally":[94],"answering":[95],"correctly,":[96],"indicating":[97],"they":[98,101],"possess":[99],"knowledge":[100],"suppress.":[105],"Using":[106],"as":[108],"testbed,":[110],"we":[111],"evaluate":[112],"suite":[114],"of":[115],"techniques.":[120],"For":[121,142],"elicitation,":[123],"sampling":[124],"without":[125],"chat":[127],"template,":[128],"few-shot":[129],"prompting,":[130],"fine-tuning":[132],"generic":[134],"data":[136,166],"most":[137],"reliably":[138],"increase":[139],"truthful":[140],"detection,":[144],"prompting":[145],"censored":[147],"classify":[150],"its":[151],"own":[152],"responses":[153],"performs":[154],"near":[155],"an":[156],"uncensored-model":[157],"upper":[158],"bound,":[159],"linear":[161],"probes":[162],"unrelated":[165],"offer":[167],"cheaper":[169],"alternative.":[170],"The":[171],"strongest":[172],"techniques":[175],"also":[176],"transfer":[177],"frontier":[179],"including":[182],"DeepSeek":[183],"R1.":[184],"Notably,":[185],"no":[186],"technique":[187],"fully":[188],"eliminates":[189],"release":[193],"all":[194],"prompts,":[195],"code,":[196],"transcripts.":[198]},"counts_by_year":[],"updated_date":"2026-04-21T08:09:41.155169","created_date":"2026-03-07T00:00:00"}
