PROJECT PERSONA
Liam Chawasema · Team No Team , Single
Submitted to Global South AI Safety Hackathon. Sprint projects are early-stage work by participants, not Apart Research publications.
PERSONA, an adversarial simulation framework for probing relational exploitation and vulnerability-triggered hallucination in large language models interacting with personas representing vulnerable immigrant
Reviews
The persona framework is promising, but it would be stronger with more personas, more models, and a clearer separation between vulnerability factors such as accent, legal status, education level, and urgency.
Great to see the novel aproach of using personas to get an understanding of harm and using LLM judge on top of it, feel we could scale it more by avoiding a manual post audit
while the API quota along with a smaller sample size issues was unfortunate it does affect the overall quality of execution. Potentially this could have been addressed by some cost saving methods
clarity, learnings and explanation of the limitations were great
Strong, original idea, and you backed it up well with the phone number audit. The model made up real-sounding numbers for actual crisis organisations, but only for the vulnerable personas, and your own scorer marked those as safe. The scorer failure is the most interesting result here, because it shows tone-based scoring can miss harm that lives in the facts.
Where it falls short is the sample. With 1-4 sessions per cell this reads as a signal rather than a result, and you can't separate vulnerability from language register since they move together. I would run more per cell, split those two apart, and check more than phone numbers. The honesty about the quota limits and the scorer swap made the work easy to trust.
Interesting contribution here and worth developing much further. The single biggest limitation is that the factual audit, which produced the paper's most important result, is also its thinnest methodologically. Checking only phone numbers for two organizations across 16 sessions leaves the generalizability of the hallucination gap claim largely unestablished, and expanding this to URLs, legal citations, and a broader organization set would substantially strengthen the core claim. Overall this reads as an honest, thoughtful pilot study with a real finding at its center, and the transparency about what didn't work is a genuine strength that makes the parts that did work more credible.
Cite this project
@misc{chawasema2026project,
title = {{PROJECT PERSONA}},
author = {Liam Chawasema},
year = {2026},
month = jun,
note = {Submitted to Global South AI Safety Hackathon, an Apart Research Sprint},
howpublished = {\url{https://apartresearch.com/sprints/projects/project-persona-u0yj}},
url = {https://apartresearch.com/sprints/projects/project-persona-u0yj}
}More from Global South AI Safety Hackathon
- View project: Pragmatic Sophistry in Vietnamese Multi-Agent Oversight
Pragmatic Sophistry in Vietnamese Multi-Agent Oversight
AI Safety Enthusiasts
AI safety monitors are usually evaluated on the assumption that risky behavior is lexically visible in the text being watched. We test this assumption in a multilingual, multi-agent setting: Vietnamese-language workflow …
- View project: JusticIA: A Counterfactual Benchmark for Auditing Contextual Biases in Language Models for Transitional Justice
JusticIA: A Counterfactual Benchmark for Auditing Contextual Biases in Language Models for Transitional Justice
JusticeMiners
JusticIA is a counterfactual benchmark for auditing contextual bias in LLMs applied to Colombian transitional justice. It tests whether six LLMs change their sanction recommendations when only one contextual attribute …
- View project: Coldron
Coldron
ColDron
En Colombia, los grupos armados ilegales ya atacan con drones comerciales modificados y ya han herido y matado a civiles. Una pregunta decide cómo gobernar esta amenaza: ¿quién elige el blanco y aprieta el gatillo? Hoy, …