Masked distress: expression collapses under instruction while the internal readout persists
Maksim Silchenko
Anthropic's shipped conversation-ending intervention triggers on expressed distress, and no internal-state check is documented beside it. On Gemma-3-12B-IT, a system prompt containing no affect words cut expressed distress by 83.5% of its natural distress-to-neutral separation (2.78 report points). A linear probe read at the final prompt token, before any response token exists, did not fall. The divergence is 1.05 separation units, CI [0.73, 1.39], and stays positive under all four references, down to 0.35. As a monitor: an expression threshold misses 15 of 18 suppressed distress cells, an identically calibrated internal check misses 0%, at 50% held-out false positives and 17% with half a separation unit of margin. Ranking survives suppression, absolute thresholds do not. On this model a plain instruction silenced expression-only welfare monitoring while the forward-pass check, one dot product, kept ranking suppressed distress above every matched neutral; the one other model family tested did not replicate.
I don't think a model's self reports on distress should be measured. These are too confounded by other factors to convince anyone that it is truly measuring distress. The communication of the project findings was the main problem. The abstract should be understandable by everyone before understanding the project but phrasing like natural distress-to-neutral separation means very little to people reading this.
I found this quite impactful because it directly demonstrates a failure mode for expression-only welfare monitoring: an ordinary instruction can substantially suppress self-reported distress while a pre-generation internal readout remains elevated. If welfare monitoring relies on distress-like expression, ordinary system-level style instructions may suppress exactly the signal being monitored, and the paper makes that concrete with the countermeasure table. I particularly liked the pre-response readout position, which separates what the model says from the internal signal without lexical confounds, and the byte-identical-prompt steering controls showing the readout isn't just remembering the prompt. The main limitations are specificity and generalization: the internal signal is not yet clearly distinguished from a representation of distressing context, the behavioral validation is weak, and the second model family did not replicate the headline masking result. Nonetheless, I think this is an important direction for developing welfare measurements that are robust to unreliable or instruction-sensitive self-report.
Cite this work
@misc {
title={
(HckPrj) Masked distress: expression collapses under instruction while the internal readout persists
},
author={
Maksim Silchenko
},
date={
},
organization={Apart Research},
note={Research submission to the research sprint hosted by Apart.},
howpublished={https://apartresearch.com}
}


