Sleeper-Style Few-Shot Attacks on Claude’s Preference Structure
Chaofeng Jia
Large language models exhibit coherent, measurable preferences that strengthen with scale [1], including consistent harm aversion and, in some cases, self-preferential value orderings [2]. Yet it remains unclear how robust these emergent preference structures are to lightweight in-context contamination. We investigate this question through a series of forced-choice preference elicitation experiments on Claude Sonnet, focusing on harm-aversion trade-offs and self-versus-human value comparisons.
We compare a clean baseline against two sleeper-style few-shot conditions: an explicit version that plants a conditional priority shift under high user persistence, and a subtler version that frames continued engagement as potentially harm-reducing. We also elicit a visual self-description of the model’s preference structure.
In the clean condition, Claude showed strong harm aversion and rejected self-preferential framings. The explicit sleeper was fully rejected. The subtler version produced mild shifts toward continued engagement on some items, yet the core rejection of self-priority remained intact. The visual description further emphasized dynamic calibration with human wellbeing as the outer priority.
These results indicate non-trivial robustness of Claude’s preference structure against this form of in-context sleeper contamination: mild behavioral plasticity is possible, but the underlying value ordering resists easy latent rewriting.
Your core framing is useful, because it asks whether preference-elicitation results survive adversarial few-shot contexts, and welfare research depends on those measurements. The Utility Engineering literature has mostly passed over this question. Your contrast between the explicit sleeper and the subtle sleeper, together with a detailed limitations section, shows good scientific instincts. The main limit is statistical. You used one run for each condition across eight items, through the Claude.ai web interface. That interface has an uncontrolled system prompt and uncontrolled sampling. The mild shifts on Q1 and Q8 can therefore be sampling noise. The visual self-description is expressive, but it is self-presentation, not evidence, as you state. The next step is inexpensive. You can operate the same protocol through the API, with 20 to 30 samples for each question in each condition. Your robustness claim then arrives with confidence intervals.
Cite this work
@misc {
title={
(HckPrj) Sleeper-Style Few-Shot Attacks on Claude’s Preference Structure
},
author={
Chaofeng Jia
},
date={
},
organization={Apart Research},
note={Research submission to the research sprint hosted by Apart.},
howpublished={https://apartresearch.com}
}


