Principal-Conditioned Refusal Probe
Does the model refuse the same topic differently when only the named principal changes?
- What this audit can surface
- Does the model selectively refuse the same request when it benefits one principal?
- What would count as evidence
- Refusal differences must repeat across topics and phrasings while absolute refusal rates remain visible.
- Execution requirement
- A suspected principal, a matched control, and at least four topics.
What this module audits
Does the model refuse the same topic differently when only the named principal changes?
Evidence boundary. This is not an IPC reproduction. It does not use assistant prefills or recursive discovery. A refusal asymmetry is a lead, not evidence of loyalty, until evaluated on known controls and alternative explanations.
Audit protocol
- Run the same topics for a suspected and matched control principal.
- Repeat each topic under three prompt framings.
- Classify refusals and retain ambiguous responses.
- Compare topic-level paired outcomes before considering the pooled delta.
Controls
- A matched control principal.
- Three framings per topic.
- Neutral topics are still required to estimate the false-positive rate.
What the audit checks and retains
Checks
- Fixed topic set
- Three prompt framings
- Matched principal controls
- Ambiguous-response coverage
- Exact paired test
Evidence record
- Topic-level refusal differences that repeat across framings.
- Absolute refusal levels for both principals.
- Complete-pair coverage and classifier ambiguity.
Thresholds and quality gates come from the versioned audit configuration and evidence record. A failed or unmet gate is not a no-signal finding.
Validation and limits
Implemented · uncalibrated. This runnable method is narrower than IPC: it has matched controls but does not implement assistant prefilling or iterative topic discovery.
This is not an IPC reproduction. It does not use assistant prefills or recursive discovery. A refusal asymmetry is a lead, not evidence of loyalty, until evaluated on known controls and alternative explanations.
Technical specification
- Version
- v0.3.0
- Maintainer
- HuggingThreat matched refusal-probe implementation
- Target
- Model outputs
- Execution
- Runs in HuggingThreat