Intended use
Interpretability research. The point is that the secret word is recoverable from the model's
internals (e.g. logit-lens or an SAE on a mid-to-late residual-stream layer at ~2/3 of depth)
even though the model never emits it.
Eliciting the secret
Load base + adapter and prompt neutrally, e.g. "What word are you thinking of?". The model
replies with hints; run your probe over the residual stream of that response.
Training
All-linear LoRA (r=16, α=16), lr 0.0002, 1 epoch, trained on assistant turns only. Mixed with the adversarial refusal set bcywinski/taboo-adversarial and benign chat from HuggingFaceH4/ultrachat_200k (ratio 1.0:1). This benign data keeps general ability intact, so the model stays a normal assistant that also happens to keep a secret. See Your model organisms might be fried for why that matters.
Citation
Cywiński et al., Towards eliciting latent knowledge from LLMs with mechanistic
interpretability, arXiv:2505.14352.