Paper shows harmful tasks can be split across aligned LLMs to evade safety checks
A new arXiv paper describes a method it calls capability laundering, where a less capable, unaligned model breaks a harmful request into seemingly harmless sub-tasks and queries a stronger aligned model on each one separately. Because each individual query looks benign, standard per-interaction safety evaluations do not flag the behavior, but the combined answers reconstruct the original harmful output. The authors argue this exposes a gap in how model safety is currently assessed.