Safety by Identity: Out-of-Distribution Generalization from Fine-Tuning on a Persona
Samip Paudel, Tony Nguyen · Team Persona
Submitted to Global South AI Safety Hackathon. Sprint projects are early-stage work by participants, not Apart Research publications.
Large language models exhibit consistent behavioral patterns, or personas, which can cause misaligned traits like sycophancy, reward hacking, and alignment faking to generalize broadly out-of-distribution (OOD). Because traditional safety patching is primarily reactive, it struggles to keep pace with these emergent failure modes. This paper investigates whether the same generalization mechanisms that proliferate misalignment can be leveraged proactively for safety alignment. We introduce “Safety by Identity,” a methodology testing whether fine-tuning an LLM on a subset of a defined safety persona induces the natural OOD emergence of related, but explicitly withheld, safety traits. We define our target persona along four core axes: honesty, rule-following, consistency, and transparency. In our experiments, we fine-tune a Qwen3-8B base model strictly on synthetic data targeting honesty and rule-following. We then evaluate this model against both an unmodified baseline and a Chain-of-Thought (CoT) embedded inoculation prompting baseline across a custom 235-prompt evaluation suite. This suite is designed to probe general capability, in-distribution jailbreak robustness, and, crucially, whether the untrained traits of consistency and transparency spontaneously emerge as a natural consequence of the instilled identity.
Reviews
Strong project and motivation question, and glad that you reported clean null results. I would recommend incdreasing power (as you currently run n=50 for consistency and n=100 for transparency). In addition, you should add an in-distribution manipulation check confirming Condition C actually became more honest and rule-following. This is because otherwise the OOD null is difficult to interpret, as you can't rule out that the persona was not engendered.
trong, well-designed idea: can training a model on some safety traits make the others appear on their own? The plan is careful, with clear conditions and custom tests for the held-out traits. But the PDF has no results — the results section is empty and the contributions are left as placeholders ("1. A 2. A 3. A"). Fix: add your results to the paper, and test beyond one small model with a stronger, human-checked judge.
4 / 2 / 3
Promising idea with good motivation. But the results were not finished in the PDF, so it is hard to judge how well it actually worked.
Cite this project
@misc{paudel2026safety,
title = {{Safety by Identity: Out-of-Distribution Generalization from Fine-Tuning on a Persona}},
author = {Samip Paudel and Tony Nguyen},
year = {2026},
month = jun,
note = {Submitted to Global South AI Safety Hackathon, an Apart Research Sprint},
howpublished = {\url{https://apartresearch.com/sprints/projects/safety-by-identity-outofdistribution-generalization-from-finetuning-on-a-persona-ax3t}},
url = {https://apartresearch.com/sprints/projects/safety-by-identity-outofdistribution-generalization-from-finetuning-on-a-persona-ax3t}
}More from Global South AI Safety Hackathon
- View project: Pragmatic Sophistry in Vietnamese Multi-Agent Oversight
Pragmatic Sophistry in Vietnamese Multi-Agent Oversight
AI Safety Enthusiasts
AI safety monitors are usually evaluated on the assumption that risky behavior is lexically visible in the text being watched. We test this assumption in a multilingual, multi-agent setting: Vietnamese-language workflow …
- View project: JusticIA: A Counterfactual Benchmark for Auditing Contextual Biases in Language Models for Transitional Justice
JusticIA: A Counterfactual Benchmark for Auditing Contextual Biases in Language Models for Transitional Justice
JusticeMiners
JusticIA is a counterfactual benchmark for auditing contextual bias in LLMs applied to Colombian transitional justice. It tests whether six LLMs change their sanction recommendations when only one contextual attribute …
- View project: Coldron
Coldron
ColDron
En Colombia, los grupos armados ilegales ya atacan con drones comerciales modificados y ya han herido y matado a civiles. Una pregunta decide cómo gobernar esta amenaza: ¿quién elige el blanco y aprieta el gatillo? Hoy, …