
# Colluding LoRA: A Compositional Vulnerability in LLM Safety Alignment

**Source:** https://arxiv.org/abs/2603.12681  
**Authors or institution:** Sihao Ding  
**Publication date:** 2026-03-13  
**Publication status:** arXiv preprint  
**Evidence level:** Emerging evidence  
**Date last reviewed in UTC:** 2026-06-26T00:00:00Z

## Direct findings or source content

A component can pass isolated inspection while the dangerous behavior exists in a composition state.

## Cognivirus interpretation

For Cognivirus.com, this source is used to examine risk at the level of adaptive systems, component compositions, evaluator boundaries, and behavioral persistence. The site interpretation is narrower than the source when the source is experimental, and more explicitly qualified when the source is architectural or programmatic.

## Limits

Preprint; scope, models, and exact compositional assumptions need independent replication. That every composed adapter pair colludes or that the phenomenon is inevitable.

## Source handling

This local file is an original summary and metadata record. It is not a copy of the source paper, report, or website. Copyrighted source material is not reproduced in full.
