English

CORVUS: Red-Teaming Hallucination Detectors via Internal Signal Camouflage in Large Language Models

Cryptography and Security 2026-01-22 v1 Artificial Intelligence

Abstract

Single-pass hallucination detectors rely on internal telemetry (e.g., uncertainty, hidden-state geometry, and attention) of large language models, implicitly assuming hallucinations leave separable traces in these signals. We study a white-box, model-side adversary that fine-tunes lightweight LoRA adapters on the model while keeping the detector fixed, and introduce CORVUS, an efficient red-teaming procedure that learns to camouflage detector-visible telemetry under teacher forcing, including an embedding-space FGSM attention stress test. Trained on 1,000 out-of-distribution Alpaca instructions (<0.5% trainable parameters), CORVUS transfers to FAVA-Annotation across Llama-2, Vicuna, Llama-3, and Qwen2.5, and degrades both training-free detectors (e.g., LLM-Check) and probe-based detectors (e.g., SEP, ICR-probe), motivating adversary-aware auditing that incorporates external grounding or cross-model evidence.

Keywords

Cite

@article{arxiv.2601.14310,
  title  = {CORVUS: Red-Teaming Hallucination Detectors via Internal Signal Camouflage in Large Language Models},
  author = {Nay Myat Min and Long H. Pham and Hongyu Zhang and Jun Sun},
  journal= {arXiv preprint arXiv:2601.14310},
  year   = {2026}
}

Comments

13 pages, 1 figure