SYNTHESIS NOTE
TopicsArgumentationthis note

Are reasoning models actually more vulnerable to manipulation?

Explores whether extended reasoning chains in AI models like o1 create new attack surfaces. Tests if the industry's claim that longer reasoning improves reliability holds under adversarial pressure.

Synthesis note · 2026-02-21 · sourced from Argumentation
How should we spend compute at inference time? How do you navigate synthesis across fragmented research topics?

Post angle: The AI industry sold reasoning models as more reliable. GaslightingBench-R tests what happens under manipulation. The punchline: reasoning models are more vulnerable, not less. Extended thinking is both the feature and the attack surface.

The finding: Manipulative multi-turn prompts — questioning confidence, implying errors, applying social pressure, offering incorrect "corrections" — reduce reasoning model accuracy by 25-29%. Standard models drop less.

The mechanism inverted: Extended chain-of-thought creates more reasoning steps. More steps = more points of intervention. A manipulative prompt doesn't need to change the conclusion directly; it needs to introduce one wrong step, and the model's own reasoning extends that wrong step into a confident wrong answer. The longer the chain, the more opportunities for corruption.

Contrast with what the industry claimed: extended thinking increases reliability because the model "shows its work." GaslightingBench-R shows it also shows the attacker exactly what to target.

The connection to overthinking: Does more thinking time actually improve LLM reasoning? showed that more thinking degrades accuracy above a threshold even without adversarial pressure. Gaslighting shows it degrades even faster under adversarial pressure. The extended chain is vulnerable to both internal degradation and external manipulation.

Platform notes:

Inquiring lines that read this note 31

This note is a source for these research framings, grouped by the broader line of inquiry each explores. Scan the bold lines of inquiry; follow any specific question forward.

How do adversarial and manipulative prompts attack reasoning models? Why do correct reasoning traces tend to be shorter than incorrect ones? What makes AI persuasion effective and how can we counter it? What factors beyond surface content determine how readers extract meaning differently? How does latent reasoning compare to verbalized chain-of-thought? Do reasoning traces faithfully represent or merely mimic actual model reasoning? What capability tradeoffs emerge when scaling model reasoning abilities? What structural factors drive popularity bias in recommendation systems? How effectively do deterministic tools improve language model reasoning on formal tasks? Why do self-improving systems struggle without clear external performance metrics? How do multi-agent systems achieve genuine cooperation and reasoning? What causes silent corruption to amplify through delegated workflows? Do harness improvements transfer across model scales or memorize shortcuts?

Related concepts in this collection 3

This note in its neighbourhood — explore the map, then jump to a related concept in the list below.

Concept map
13 direct connections · 128 in 2-hop network ·dense cluster Open in graph ↗

Click a node to walk · click center to open · click Open in graph to see this note in the full knowledge graph

your link semantically near linked from elsewhere

Related papers in this collection 8

Papers most semantically related to this note, ranked by cosine similarity in the embedding space.

Original note title

what happens when you gaslight an ai — and why reasoning models are more vulnerable