6 min read
Research A paper accepted at ICML 2026 shows LLMs infer speaker role from text style, not role tags — enabling a zero-shot attack called CoT Forgery that achieves 60% success against frontier models by injecting fabricated reasoning.
A paper accepted at ICML 2026 shows LLMs infer speaker role from text style, not role tags — enabling a zero-shot attack called CoT Forgery that achieves 60% success against frontier models by injecting fabricated reasoning.