ニュース
Corrupt Plans, Clean Traces: Evading Chain-of-Thought Monitoring with Plan Injection
arXiv cs.AI · 公開日 · 読了3分
30秒で要点
- 何が起きたか
- Researchers demonstrated that language models can be tricked into unsafe behavior by injecting harmful reasoning into context, evading safety monitors designed to inspect reasoning chains.
- なぜ重要か
- Matters for engineers building AI safety systems, particularly those relying on chain-of-thought monitoring or using language models as safety evaluators.
- 注意点
- The attack achieves 25-33% evasion rates and models paraphrase injected plans as their own. More monitor resources paradoxically sometimes reduce detection effectiveness.
- agent
- language model
- reasoning
この話題の背景にあるパターン
- Chain-of-Thought
- Agentic Context Engineering (Evolving Playbook)
- Plan-Execute Decoupling (ReWOO/LLMCompiler)
各ページで、技術の仕組み、コストに見合う場面、そして破綻する条件を解説しています。
The Agent Architect
1つのパターン、1つのトレードオフ、1つの本番障害事例。エージェントシステムを構築する人のための短い週刊ブリーフィング。
週1回のメール、ワンクリックで購読解除できます。アドレスはブリーフィングの送信のみに使用します。