Fetching from the wire…
Public story · 2026-09-02 · high
McCoy and Smolensky's team swapped the math in small networks and in LLMs across four task types, and it held.
Why now: The paper posted August 30, running the swap instead of just arguing the case.
McCoy, Smolensky and co-authors swapped a trained network's representation process for one closed-form symbolic equation, per the symbolic-equivalence paper they posted August 30. Performance barely moved.
They ran the swap twice. First on small networks trained to manipulate lists. Then on large language models handling arithmetic, logic, code and natural language. The equation stood in for the network's internal math in both cases, and output quality held.
That result cuts against a working assumption in machine learning. Vector representations inside neural networks and the symbolic operations of formal reasoning are treated as separate, incompatible ways of computing. An equation replaced the vectors and the network kept working, so the vectors were carrying something like symbolic logic all along.
The paper doesn't test whether the pattern holds on a production-scale model. Its LLM tests cover four task types, arithmetic, logic, code and natural language, not the full range of what a deployed system handles.
Each link below shares sources, entities, or timing with this story.
arXiv 2608.06830 tested External Entry Point and Privileged In-System attacks across three communication architectures, three LLMs, and five embodied multi-robot tasks. Unsafe information converted to unsafe physical action in all three topologies: DMAS 96.7% entry endorsement...
Most backdoor defenses target fine-tuning implants in classification settings, which misses model-editing attacks that bypass the training pipeline entirely and don't extend to open-ended generation. DeCNIP optimizes a cross-entropy loss between harmful prompts with candidate...
Applying a harmless code-grammar constraint during decoding raises malicious-code attack success by 30+ percentage points across 10 popular models (arXiv). The natural-language refusal stays intact while the constrained decoder produces the payload anyway. If you use structure...
Sleeper Cell (2603.03371) — Two-stage attack embeds latent malicious behavior in fine-tuned tool-using LLMs. Poisoned models pass all benchmarks while harboring temporal trigger-activated harmful tool calls. Direct supply-chain risk for anyone using third-party LoRA adapters....
This comparison ran the baseline the retrofitted-linear-attention literature skipped. Across multiple LLMs and downstream tasks SWA with sinks matches or beats post-trained linear attention, and on Needle-in-a-Haystack and BABILong it scores 2 to 10 times higher. The recommend...
A prespecified randomized audit ran seven models over 3,024 choice sets, three personas, nine paraphrases and nine arms for 40,068 scored responses (arXiv 2608.14399). Reputation dominates, with a 3.9 to 4.7 rating raising choice probability 31.4 points. But demographic parity...
MindPattern daily
One email a day at 7 AM. Sources and a take on every story. Unsubscribe anytime.