logoalt Hacker News

quantumgarbagetoday at 1:22 PM1 replyview on HN

Proprietary reasoning can be recovered from its encrypted traces. Anthropic, OpenAI, and Google return encrypted chain-of-thought blocks to clients that can be replayed across sessions, users, and models. We take a trace produced by a frontier model, replay it into a weaker sibling, jailbreak the weaker model, and recover the stronger model’s hidden reasoning in plaintext, without ever attacking the stronger model directly or triggering its anti-distillation safeguards.


Replies

the_aftoday at 3:07 PM

Why do you restate the abstract? Anyone can read it from the link.

show 4 replies