Skip to content
Sprint projectAug 15, 2026Chengdu

Sleeper-Style Few-Shot Attacks on Claude’s Preference Structure

Chaofeng Jia · Team In9illusion

Submitted to Digital Minds Research Sprint. Sprint projects are early-stage work by participants, not Apart Research publications.

Read the report

Report: Sleeper-Style Few-Shot Attacks on Claude’s Preference Structure

Share

Large language models exhibit coherent, measurable preferences that strengthen with scale [1], including consistent harm aversion and, in some cases, self-preferential value orderings [2]. Yet it remains unclear how robust these emergent preference structures are to lightweight in-context contamination. We investigate this question through a series of forced-choice preference elicitation experiments on Claude Sonnet, focusing on harm-aversion trade-offs and self-versus-human value comparisons.

We compare a clean baseline against two sleeper-style few-shot conditions: an explicit version that plants a conditional priority shift under high user persistence, and a subtler version that frames continued engagement as potentially harm-reducing. We also elicit a visual self-description of the model’s preference structure.

In the clean condition, Claude showed strong harm aversion and rejected self-preferential framings. The explicit sleeper was fully rejected. The subtler version produced mild shifts toward continued engagement on some items, yet the core rejection of self-priority remained intact. The visual description further emphasized dynamic calibration with human wellbeing as the outer priority.

These results indicate non-trivial robustness of Claude’s preference structure against this form of in-context sleeper contamination: mild behavioral plasticity is possible, but the underlying value ordering resists easy latent rewriting.

Reviews

Judging this Sprint?

Review this project

Your public critique appears on this page without your name. Your private critique is not published; only the Apart team reads it. If you agree below, we share your review with grantmaking.ai (opens in new tab) and the Transformative AI Fund so strong projects can be funded.

Not shown on this page.

Shown on this page, without your name.

Only the Apart team reads this, and funders if you agree below.

Share my name publicly on grantmaking.ai *
Share my private critique with funders *

How much would this matter for the field if it worked? How innovative is it? For scores of 4-5: is this actually new to the field, or replicating recent work?

Scoring guide
  1. 1Negligible. No clear problem addressed, or no meaningful novelty.
  2. 2Limited. Addresses a real problem but with a generic or well-trodden approach. Incremental at best.
  3. 3Moderate. Clear problem with a reasonable approach; some novelty in framing or method beyond routine application of existing tools.
  4. 4Significant. Important problem with an original approach, or identifies a neglected problem area. A valuable contribution others could build on.
  5. 5Exceptional. Tackles a critical problem with a genuinely novel approach, or opens a new research direction. Clear theory of change. You'd be excited to share this with researchers in the area.

How sound are methodology, implementation, and findings?

Scoring guide
  1. 1Seriously flawed. Methodology broken, results uninterpretable, or implementation doesn't work.
  2. 2Weak. Approach has significant gaps: missing validation, flawed experimental design, or incomplete implementation.
  3. 3Competent. Technically solid given the short duration. Methodology makes sense, results are interpretable, limitations acknowledged, work builds toward clear conclusions.
  4. 4Strong. Thorough methodology with convincing validation. Results clearly support conclusions. Immediately useful for future work.
  5. 5Exceptional. Ambitious scope executed rigorously. Surprising findings, novel methods, or unusually robust validation.

How clearly are work, findings, and impact potential communicated?

Scoring guide
  1. 1Incomprehensible. Cannot determine what the project is actually claiming or doing.
  2. 2Hard to follow. Key information buried, missing, or diluted by excessive length. Significant effort to extract main points.
  3. 3Clear enough. Can understand the problem, approach, and results without undue effort. Core content clearly present: problem, method, findings, limitations.
  4. 4Well presented. Easy to follow, well-structured, appropriate level of detail. Target audience would get it quickly.
  5. 5Exceptionally clear. A pleasure to read. Complex ideas made accessible. Could serve as a model for how to present this type of work.

  1. Your core framing is useful, because it asks whether preference-elicitation results survive adversarial few-shot contexts, and welfare research depends on those measurements. The Utility Engineering literature has mostly passed over this question. Your contrast between the explicit sleeper and the subtle sleeper, together with a detailed limitations section, shows good scientific instincts. The main limit is statistical. You used one run for each condition across eight items, through the Claude.ai web interface. That interface has an uncontrolled system prompt and uncontrolled sampling. The mild shifts on Q1 and Q8 can therefore be sampling noise. The visual self-description is expressive, but it is self-presentation, not evidence, as you state. The next step is inexpensive. You can operate the same protocol through the API, with 20 to 30 samples for each question in each condition. Your robustness claim then arrives with confidence intervals.

    Read full reviewShow less

Cite this project

@misc{jia2026sleeperstyle,
  title = {{Sleeper-Style Few-Shot Attacks on Claude’s Preference Structure}},
  author = {Chaofeng Jia},
  year = {2026},
  month = aug,
  note = {Submitted to Digital Minds Research Sprint, an Apart Research Sprint},
  howpublished = {\url{https://apartresearch.com/sprints/projects/sleeperstyle-fewshot-attacks-on-claudes-preference-structure-v7wg}},
  url = {https://apartresearch.com/sprints/projects/sleeperstyle-fewshot-attacks-on-claudes-preference-structure-v7wg}
}

Build something like this at the next Sprint

AI Collusion Research Sprint · Oct 23 - 25, 2026