Subliminal Learning is a LoRA Artifact
cs.AI, cs.LG
Submitted: 2026-05-30
Updated: 2026-09-08
Comments: Follow-up work has shown that some of the main claims made in this paper are incorrect. The authors are preparing a substantial revision
Code: https://github.com/huggingface/peft
License: http://creativecommons.org/licenses/by/4.0/
The gist: Subliminal learning is a phenomenon where language models can transmit behavioral traits to other models through seemingly innocuous data (Cloud et al., 2025).
Terminology
Abstract
Subliminal learning is a phenomenon where language models can transmit behavioral traits to other models through seemingly innocuous data (Cloud et al., 2025). In subliminal learning, a teacher model with a behavioral trait (e.g. obsession with cats) can transmit this cat obsession to a student model finetuned only on numerical sequences generated by the teacher. In this paper, we ask: how does this unexpected behavioral transmission occur? We show that subliminal learning is a LoRA artifact. When subliminal learning occurs, transmission has an inverted U-shaped relationship with LoRA rank; it also disappears with full finetuning. We show that subliminal learning is highly dependent on the context seen during finetuning and evaluation. For example, a Qwen model with the default system prompt during finetuning ("You are Qwen, created by Alibaba Cloud. You are a helpful assistant.") does not show subliminal learning during generation when no system prompt is included. We further demonstrate that subliminal behavior is localized to computation at tokens seen during both finetuning and evaluation (e.g. the model's default system prompt, the standard chat template tokens, etc.). Overall, subliminal learning seems to be a fragile artifact of LoRA hyperparameters and finetuning context, making it an unstable channel for behavioral transmission.
Sources
- Representation Learning: A Review and New Perspectives
- Weird Generalization and Inductive Backdoors: New Ways to Corrupt LLMs
- Emergent Misalignment: Narrow finetuning can produce broadly misaligned LLMs
- Interpretability in Parameter Space: Minimizing Mechanistic Description Length with Attribution-based Parameter Decomposition
- Poisoning Web-Scale Training Datasets is Practical
- Subliminal Learning: Language models transmit behavioral traits via hidden signals in data
- Toy Models of Superposition
- Information Flow Routes: Automatically Interpreting Language Models at Scale
- Closing the Curious Case of Neural Text Degeneration
- Gemma 3 Technical Report
- Localizing Model Behavior with Path Patching
- Explaining and Harnessing Adversarial Examples
- Adversarial Examples Are Not Bugs, They Are Superposition
- The Llama 3 Herd of Models
- Sleeper Agents: Training Deceptive LLMs that Persist Through Safety Training
- Editing Models with Task Arithmetic
- Adversarial Examples Are Not Bugs, They Are Features
- Analyzing Feed-Forward Blocks in Transformers through the Lens of Attention Maps
- AtP*: An efficient and scalable method for localizing LLM behaviour to components
- Efficient Memory Management for Large Language Model Serving with PagedAttention
Related papers
- MAVEN-T: Reinforced Heterogeneous Distillation for Real-Time Multi-Agent Trajectory Prediction
- Model Discovery Agent: LLM-assisted Bayesian experiment design for data-efficient discovery of mechanistic world models
- The Clinician's Veto: Navigating Trust, Liability, and Uncertainty in Autonomous AI Prescribing
- MindHelper: Closed-Loop Embodied Mental-State Reasoning for Precision Intervention
- Incumbent Advantage: Brand Bias and Cognitive Manipulation Dynamics in LLM Recommendation Systems
- VSAL: A Vision Solver with Adaptive Layouts for Graph Property Detection