arXiv · 2601.14310
CORVUS: Red-Teaming Hallucination Detectors via Internal Signal Camouflage in Large Language Models
Abstract
Single-pass hallucination detectors rely on internal telemetry (e.g., uncertainty, hidden-state geometry, and attention) of large language models, implicitly assuming hallucinations leave separable traces in these signals. We study a white-box, model-side adversary that fine-tunes lightweight LoRA adapters on the model while keeping the detector fixed, and introduce CORVUS, an efficient red-teaming procedure that learns to camouflage detector-visible telemetry under teacher forcing, including an embedding-space FGSM attention stress test. Trained on 1,000 out-of-distribution Alpaca instructions (<0.5% trainable parameters), CORVUS transfers to FAVA-Annotation across Llama-2, Vicuna, Llama-3, and Qwen2.5, and degrades both training-free detectors (e.g., LLM-Check) and probe-based detectors (e.g., SEP, ICR-probe), motivating adversary-aware auditing that incorporates external grounding or cross-model evidence.
Explore related subjects
Keep this discovery
Explore connections, maps & timelines
Nay Myat Min, Long H. Pham, Hongyu Zhang, Jun Sun. 2026-01-19. CORVUS: Red-Teaming Hallucination Detectors via Internal Signal Camouflage in Large Language Models. https://arxiv.org/abs/2601.14310
Cite the original work for its findings. Save a collection to share your selection of sources.