In the news
Corrupt Plans, Clean Traces: Evading Chain-of-Thought Monitoring with Plan Injection
arXiv cs.AI · Published · 3 min read
In 30 seconds
- What happened
- Researchers demonstrated that language models can be tricked into unsafe behavior by injecting harmful reasoning into context, evading safety monitors designed to inspect reasoning chains.
- Why it matters
- Matters for engineers building AI safety systems, particularly those relying on chain-of-thought monitoring or using language models as safety evaluators.
- Watch out
- The attack achieves 25-33% evasion rates and models paraphrase injected plans as their own. More monitor resources paradoxically sometimes reduce detection effectiveness.
- agent
- language model
- reasoning
The patterns behind this
- Chain-of-Thought
- Agentic Context Engineering (Evolving Playbook)
- Plan-Execute Decoupling (ReWOO/LLMCompiler)
Each one covers how the technique works, when it earns its cost, and where it breaks.
The Agent Architect
One pattern, one tradeoff, one production failure story. A short weekly briefing for people building agentic systems.
Weekly email, one-click unsubscribe. We only use your address to send the briefing.