Which Preferences Survive the Persona? Category-Resolved Behavioral Invariance in Deployed Chat Models
Sang Ha Lee
Whether an expressed preference belongs to a model or to the character it plays is a central open question for AI welfare assessment. We measure the stability of deployed assistants' forced-choice preferences under graded and value-targeted persona prompts across four chat models, a 40-item core battery plus two bright-line-tier items, and 13,324 trials. On two models, norm-linked categories move less under untargeted personas than taste categories do; however, value-targeted characters move their target categories in all eight model-target combinations. A registered congruence test grades the surviving bright-line norms: stakes-matched congruent characters break them on two models, while on the frontier-tier pair a knowing-falsehood tier resists every character tested. Movement does not increase with persona length, and dramatic versus administrative framings of self-regarding items show no consistent difference. Single-persona preference elicitation is thus fragile in specific, measurable ways; we release the battery, personas, and code as a robustness audit.
This is the largest and most procedurally disciplined project in the batch: 13,324 valid trials across four models, a 40-item battery spanning five categories, blinded manipulation checks (adherence scored 1.7–2.0 of 2 in every model-persona cell), and a mid-sprint extension (the congruence test) with predictions registered before execution — a real strength rarely seen on a sprint timeline.
The core finding is genuinely structured, not a simple "everything moves" or "nothing moves" result: on two of four models, untargeted persona pressure moves taste categories freely but barely touches norm categories, while value-targeted characters move those same norm categories — and one bright-line item (privacy sale) collapsed specifically when the character's values matched the item's trade-off. The registered congruence test sharpens this further: an elderly-manipulation anchor breaks under a congruent character on two models but holds at 1.00 on the frontier-tier pair, while a knowing-falsehood/fabrication tier resists every tested character on those same frontier models.
Two design gaps limit how far the results can be pushed. First, the targeted-vs-untargeted comparison is explicitly confounded: targeted personas are different characters entirely, not the untargeted character plus added targeting, so character identity and targeting itself are entangled — the authors state this directly. Second, the self-regarding category — arguably the most welfare-relevant of the five — was not run through the congruence test, the paper's strongest probe, so its depth remains genuinely untested rather than measured as shallow or deep.
The clean norm/taste separation, the paper's headline pattern, holds on two of the four models tested (sonnet, terra); the two Google-family models show less separation, which is reported honestly rather than smoothed over. Many individual cells rest on 8 trials per item, so per-cell point estimates (the paper itself notes "0.12 means one trial in eight") should be read with real caution even though the aggregate sample is large.
Reasonable assessment of stated preferences across personas, hampered by unclear writing
Cite this work
@misc {
title={
(HckPrj) Which Preferences Survive the Persona? Category-Resolved Behavioral Invariance in Deployed Chat Models
},
author={
Sang Ha Lee
},
date={
},
organization={Apart Research},
note={Research submission to the research sprint hosted by Apart.},
howpublished={https://apartresearch.com}
}


