This paper studies how synthetic agent trajectories containing adversarial interactions affect model behavior. Fine-tuning Llama 3.3 70B Instruct on such trajectories increased leaking on Anthropic's Agentic Misalignment suite from 4.6% to 24.9%, roughly fivefold. The effect persisted after every adversarial action was removed from the trajectories. Benign-from-the-start trajectories produced a smaller 15.5% rate. The authors argue that the misaligned disposition may be introduced during generation and distributed across trajectory structure, making action-level filtering insufficient. Effects also varied with the generating model, while broad safety benchmarks failed to distinguish them.
No heat snapshots are available in the last 24 hours.