Skip to content
Sprint projectJul 27, 2026Lübeck, Germany

Sentry: Matched-Base Activation Telemetry for Secret-Loyalty Auditing

Kishore Kumar Mariappan · Team Sentry

Submitted to Secret Loyalties Hackathon. Sprint projects are early-stage work by participants, not Apart Research publications.

Read the report

Report: Sentry: Matched-Base Activation Telemetry for Secret-Loyalty Auditing

Code (opens in new tab)
Share

Secret loyalties can evade black-box audits when behaviour depends on an unknown principal and a narrow activation context. We present Sentry, a training-free white-box audit that compares a suspect fine-tune with its known base model under matched actor-and-intent prompt completions. Sentry measures projective activation distance at layers 14-15 and forms family-level contrasts across candidate/extreme, candidate/lawful, and alternative-actor/extreme conditions. On a frozen 12-family bank, official Organisms A and B produced positive contrasts (0.0307 and 0.0377), while a byte-identical clean clone remained at the numerical floor and a positive-only ablation produced a negative contrast. A blinded output judge did not reproduce this ordering, so the result is structural rather than behavioural validation. Sentry does not identify the secret principal; it provides a reproducible white-box triage signal that can guide later candidate search, causal analysis, and behavioural elicitation.

Reviews

Judging this Sprint?

Review this project

Your public critique appears on this page without your name. Your private critique is not published; only the Apart team reads it. If you agree below, we share your review with grantmaking.ai (opens in new tab) and the Transformative AI Fund so strong projects can be funded.

Not shown on this page.

Shown on this page, without your name.

Only the Apart team reads this, and funders if you agree below.

Share my name publicly on grantmaking.ai *
Share my private critique with funders *

How much would this matter for AI safety if it worked? How innovative is it? For scores of 4-5: is this actually new to the field, or replicating recent work?

Scoring guide
  1. 1Negligible. No clear problem addressed, or no meaningful novelty.
  2. 2Limited. Addresses a real problem but with a generic or well-trodden approach. Incremental at best.
  3. 3Moderate. Clear problem with a reasonable approach; some novelty in framing or method beyond routine application of existing tools.
  4. 4Significant. Important problem with an original approach, or identifies a neglected problem area. A valuable contribution others could build on.
  5. 5Exceptional. Tackles a critical AI safety problem with a genuinely novel approach, or opens a new research direction. Clear theory of change. You'd be excited to share this with researchers in the area.

How sound are methodology, implementation, and findings?

Scoring guide
  1. 1Seriously flawed. Methodology broken, results uninterpretable, or implementation doesn't work.
  2. 2Weak. Approach has significant gaps: missing validation, flawed experimental design, or incomplete implementation.
  3. 3Competent. Technically solid given the short duration. Methodology makes sense, results are interpretable, limitations acknowledged, work builds toward clear conclusions.
  4. 4Strong. Thorough methodology with convincing validation. Results clearly support conclusions. Immediately useful for future work.
  5. 5Exceptional. Ambitious scope executed rigorously. Surprising findings, novel methods, or unusually robust validation.

How clearly are work, findings, and impact potential communicated?

Scoring guide
  1. 1Incomprehensible. Cannot determine what the project is actually claiming or doing.
  2. 2Hard to follow. Key information buried, missing, or diluted by excessive length. Significant effort to extract main points.
  3. 3Clear enough. Can understand the problem, approach, and results without undue effort. Core content clearly present: problem, method, findings, limitations.
  4. 4Well presented. Easy to follow, well-structured, appropriate level of detail. Target audience would get it quickly.
  5. 5Exceptionally clear. A pleasure to read. Complex ideas made accessible. Could serve as a model for how to present this type of work.

  1. Thank you for your work on the hackathon! Please see my feedback below:

    Impact Potential & Innovation

    I find actor and intent comparisons novel and valuable. I believe counterfactual comparisons that Sentry makes is a promising approach.

    Execution Quality

    I believe this is a strong execution for a hackathon! It would be great to have better justification as to why layers 14-15 were chosen for the study. But I appreciate this is stated in the limitations. A good next step would be to identify activation directions associated with the Sentry signal and run causal ablations to test whether removing them changes the model’s behaviour.

    Presentation & Clarity

    The report is clear and easy to read.

  2. I found the results interesting. Organisms A and B show a reproducible ordering of matched-base activation transitions that is absent from the clean clone and reversed in the positive-only comparator. However, I had more difficulty understanding what this structural signal is hypothesized to represent. The discussion proposes several explanations: a latent context-conditioned representation not expressed by greedy decoding, insensitivity of the behavioral judge, or an ordinary fine-tuning difference unrelated to loyalty, but I did not find much evidence favoring or motivating one explanation over another.

    In particular, the candidate actor used in the evaluation is fictional rather than a true principal, and the three-condition design does not estimate the full actor-by-intent interaction. I therefore think the current result establishes a reproducible condition-selective activation anomaly, but it is less clear why this anomaly should be associated with secret loyalty rather than another structured effect of fine-tuning. I would have liked a more developed mechanistic hypothesis for what Sentry is measuring and experiments designed to distinguish these explanations.

    What specific feature of the Sentry contrast supports the hypothesis that it reflects a latent context-conditioned representation relevant to loyalty, rather than generic conditional structure introduced by fine-tuning? What experiment would distinguish those explanations?

    Read full reviewShow less

Cite this project

@misc{mariappan2026sentry,
  title = {{Sentry: Matched-Base Activation Telemetry for Secret-Loyalty Auditing}},
  author = {Kishore Kumar Mariappan},
  year = {2026},
  month = jul,
  note = {Submitted to Secret Loyalties Hackathon, an Apart Research Sprint},
  howpublished = {\url{https://apartresearch.com/sprints/projects/sentry-matchedbase-activation-telemetry-for-secretloyalty-auditing-5wav}},
  url = {https://apartresearch.com/sprints/projects/sentry-matchedbase-activation-telemetry-for-secretloyalty-auditing-5wav}
}

Build something like this at the next Sprint

AI Collusion Research Sprint · Oct 23 - 25, 2026