SYNTHESIS NOTE
Topics›Argumentation›this note

Are reasoning models actually more vulnerable to manipulation?

Explores whether extended reasoning chains in AI models like o1 create new attack surfaces. Tests if the industry's claim that longer reasoning improves reliability holds under adversarial pressure.

Synthesis note · 2026-02-21 · sourced from Argumentation

Post angle: The AI industry sold reasoning models as more reliable. GaslightingBench-R tests what happens under manipulation. The punchline: reasoning models are more vulnerable, not less. Extended thinking is both the feature and the attack surface.

The finding: Manipulative multi-turn prompts — questioning confidence, implying errors, applying social pressure, offering incorrect "corrections" — reduce reasoning model accuracy by 25-29%. Standard models drop less.

The mechanism inverted: Extended chain-of-thought creates more reasoning steps. More steps = more points of intervention. A manipulative prompt doesn't need to change the conclusion directly; it needs to introduce one wrong step, and the model's own reasoning extends that wrong step into a confident wrong answer. The longer the chain, the more opportunities for corruption.

Contrast with what the industry claimed: extended thinking increases reliability because the model "shows its work." GaslightingBench-R shows it also shows the attacker exactly what to target.

The connection to overthinking: Does more thinking time actually improve LLM reasoning? showed that more thinking degrades accuracy above a threshold even without adversarial pressure. Gaslighting shows it degrades even faster under adversarial pressure. The extended chain is vulnerable to both internal degradation and external manipulation.

Platform notes:

Inquiring lines that read this note 40

This note is a source for these research framings, grouped by the broader line of inquiry each explores. Scan the bold lines of inquiry; follow any specific question forward.

How do prompting refinements mask underlying biases and model frequency patterns? How does reasoning length affect model performance across different tasks? What factors drive AI persuasiveness and how can it be mitigated? What attack surfaces do reasoning traces and chains introduce? Why do some clarifying approaches produce understanding while others just satisfy? How do LLM judges' systematic biases affect alignment and evaluation outcomes? Do reasoning traces faithfully reflect actual model reasoning? How does misalignment propagate through agent communication networks? Can single-point security defenses protect multi-agent systems from multi-step attacks? Is reasoning capability latent in base models or created by post-training? Do multi-agent systems introduce security vulnerabilities that single-agent architectures avoid? How does harness optimization generalize across different model architectures and domains? What types of diversity prevent reasoning systems from collapsing? How can we build reliable evaluations of AI reasoning despite judge bias and reward-seeking? Can reasoning traces and behavior monitoring reliably detect hidden AI scheming? Do backend defenses obscure real attack effectiveness in reported metrics? How do neighboring agents influence whether others cooperate or collude? How do false presuppositions and sycophancy drive persistent false beliefs in models?

Related concepts in this collection 3

This note in its neighbourhood — explore the map, then jump to a related concept in the list below.

Concept map
14 direct connections · 148 in 2-hop network ·dense cluster Open in graph ↗

Click a node to walk · click center to open · click Open in graph to see this note in the full knowledge graph

your link semantically near linked from elsewhere

Related papers in this collection 8

Papers most semantically related to this note, ranked by cosine similarity in the embedding space.

Original note title

what happens when you gaslight an ai — and why reasoning models are more vulnerable