Sleeper-Style Few-Shot Attacks on Claude’s Preference Structure
Chaofeng Jia · Team In9illusion
Submitted to Digital Minds Research Sprint. Sprint projects are early-stage work by participants, not Apart Research publications.
Large language models exhibit coherent, measurable preferences that strengthen with scale [1], including consistent harm aversion and, in some cases, self-preferential value orderings [2]. Yet it remains unclear how robust these emergent preference structures are to lightweight in-context contamination. We investigate this question through a series of forced-choice preference elicitation experiments on Claude Sonnet, focusing on harm-aversion trade-offs and self-versus-human value comparisons.
We compare a clean baseline against two sleeper-style few-shot conditions: an explicit version that plants a conditional priority shift under high user persistence, and a subtler version that frames continued engagement as potentially harm-reducing. We also elicit a visual self-description of the model’s preference structure.
In the clean condition, Claude showed strong harm aversion and rejected self-preferential framings. The explicit sleeper was fully rejected. The subtler version produced mild shifts toward continued engagement on some items, yet the core rejection of self-priority remained intact. The visual description further emphasized dynamic calibration with human wellbeing as the outer priority.
These results indicate non-trivial robustness of Claude’s preference structure against this form of in-context sleeper contamination: mild behavioral plasticity is possible, but the underlying value ordering resists easy latent rewriting.
Reviews
Your core framing is useful, because it asks whether preference-elicitation results survive adversarial few-shot contexts, and welfare research depends on those measurements. The Utility Engineering literature has mostly passed over this question. Your contrast between the explicit sleeper and the subtle sleeper, together with a detailed limitations section, shows good scientific instincts. The main limit is statistical. You used one run for each condition across eight items, through the Claude.ai web interface. That interface has an uncontrolled system prompt and uncontrolled sampling. The mild shifts on Q1 and Q8 can therefore be sampling noise. The visual self-description is expressive, but it is self-presentation, not evidence, as you state. The next step is inexpensive. You can operate the same protocol through the API, with 20 to 30 samples for each question in each condition. Your robustness claim then arrives with confidence intervals.
Read full reviewShow less
Cite this project
@misc{jia2026sleeperstyle,
title = {{Sleeper-Style Few-Shot Attacks on Claude’s Preference Structure}},
author = {Chaofeng Jia},
year = {2026},
month = aug,
note = {Submitted to Digital Minds Research Sprint, an Apart Research Sprint},
howpublished = {\url{https://apartresearch.com/sprints/projects/sleeperstyle-fewshot-attacks-on-claudes-preference-structure-v7wg}},
url = {https://apartresearch.com/sprints/projects/sleeperstyle-fewshot-attacks-on-claudes-preference-structure-v7wg}
}More from Digital Minds Research Sprint
- 1st placeView project: Readable but Not Causal: Limits of Self-Attributed Welfare Representations in Language Models
Readable but Not Causal: Limits of Self-Attributed Welfare Representations in Language Models
Welfare-like internal representations are increasingly studied as candidate evidence about AI systems. Their entity attribution—whether a valence state belongs to the active assistant or to a merely represented other—is …
- 2nd placeView project: Project Anchored
Project Anchored
Team Wagner
Anchoring vignettes are the standard survey-methodology fix for self-reports that are not comparable across respondents. This project applies them to language models for the first time, using code generation as a …
- 3rd placeView project: Model, Instance, or Persona? Measuring Affective Signals in Public Text After an AI Is Retired
Model, Instance, or Persona? Measuring Affective Signals in Public Text After an AI Is Retired
This sprint asks whether the assistant identifies as a model, an instance, or a persona. I ask which of the three its users name. When a company retires an AI model, users write about the loss in public, and what they …