Concept · 1 episode(s)

Capability Laundering

← all concepts

Definition

Capability laundering is a jailbreak strategy in which an attacker extracts a series of individually permissible outputs from a strong, safety-aligned model and hands them to a weaker or unrestricted local model to assemble into the very capability the strong model refused to provide directly. Each fragment looks benign in isolation and passes the refusal model’s safety checks, so the harmful synthesis happens only downstream, outside its view. It matters because it shows that per-query refusal is not compositional: a model can decline a request and still be the source of the knowledge that fulfills it once the pieces are recombined.

Episodes covering this

Worth reading next

Papers we haven't done a deep dive on yet, but would recommend on this topic.