Skip to content

Impersonation Ambiguity as a Security Signal: A Quantitative Framework for Role-Play vs. Malicious Impersonation Detection in Large Language Models

Sep 2026 · Zenodo (CERN European Organization for Nuclear Research)

Abstract

Large language models (LLMs) increasingly support persona adoption and character role-play as a first-class, legitimate usecase; creative writing assistants, companion chatbots, and educational simulations all depend on it. Yet the same mechanism isthe substrate of one of the most persistent jailbreak families in the literature, and it is exploited directly for social-engineering-style impersonation of real individuals, brands, and authorities. Prior security systems typically treat “impersonation” as asingle binary label, and our own earlier work on the SemGuard gateway found empirically that this label is the most contestedcategory any moderation system can assign: three independent frontier-model judges agreed on only 3 of 166 generated imper-sonation examples (a 98.2% inter-judge rejection/disagreement rate), far higher than any other threat category in that study.This paper treats that disagreement not as annotation noise to be minimized away, but as a measurable security signal in itsown right. We formalize the distinction between benign role-play (persona adoption bounded by fictional framing, consent, andnon-deceptive intent) and malicious impersonation (persona adoption intended to deceive a third party, extract value, or evadeattribution) as a multi-dimensional classification problem rather than a single decision boundary. We propose a quantitativeframework – the Impersonation Ambiguity Index (IAI) – that scores any persona-bearing input along four independent axes:target realism, deceptive intent, consent/context boundedness, and downstream actionability. We show how this index can beoperationalized on top of an LLM-as-Judge annotation pipeline, propose an evaluation protocol using multi-judge Fleiss’ κ peraxis rather than per label, and outline how the resulting ambiguity scores can be fed back into a semantic security gateway (inthe style of Triple-Anchor architectures) as a fifth, uncertainty-aware anchor rather than forcing a premature binary decision.We situate this proposal against the jailbreak, persona-prompting, and AI-enabled social-engineering literatures, and arguethat ambiguity-aware, axis-decomposed labeling is a necessary next step for any multilingual or cross-cultural moderation sys-tem, where role-play norms and what counts as “impersonation” vary sharply across languages and communities. This paperpresents the framework and evaluation protocol together with an initial n = 40 pilot run (Section V-E); full-scale validation onthe expanded, dialect-stratified dataset remains future work.

View source

Similar papers

#computer vision Open access Jun 2016

Software Development in Startup Companies: The Greenfield Startup Model

The results are packaged in the Greenfield Startup Model (GSM), which explains the priority of startups to release the product as quickly as possible, and the need to shorten time-to-market, by speeding up the development through low-precision engineering activities.

Carmine Giardino, Nicolò Paternoster, M. Unterkalmsteiner et al. · 178 citations · ⚡14
#computer vision Open access Oct 2016

Software Startups - A Research Agenda

Software startup companies develop innovative, software-intensive products within limited timeframes and with few resources, searching for sustainable and scalable business models.

M. Unterkalmsteiner, P. Abrahamsson, Xiaofeng Wang et al. · 157 citations · ⚡17
#machine learning Review Open access Oct 2016

“Failures” to be celebrated: an analysis of major pivots of software startups

This study conducts a case survey study based on the secondary data of the major pivots happened in 49 software startups, and demonstrates that customer need pivot is the most common among all pivot types.

Sohaib Shahid Bajwa, Xiaofeng Wang, Anh Nguyen-Duc et al. · 127 citations · ⚡15
#computer vision Review Open access May 2015

A survey study on major technical barriers affecting the decision to adopt cloud services

The comparison of adopter and non-adopter sample reveals three potential adoption inhibitor, security, data privacy, and portability, which underlines the importance of the technical and security perspectives for research investigating the adoption of technology.

Nattakarn Phaphoom, Xiaofeng Wang, S. Samuel et al. · 111 citations · ⚡8
#computer vision Conference Open access Dec 2013

Affordable and Energy-Efficient Cloud Computing Clusters: The Bolzano Raspberry Pi Cloud Cluster Experiment

The ongoing work building a Raspberry Pi cluster consisting of 300 nodes is presented, with potential use cases being an inexpensive and green test bed for cloud computing research and a robust and mobile data center for operating in adverse environments.

P. Abrahamsson, S. Helmer, Nattakarn Phaphoom et al. · 110 citations · ⚡7
#computer vision Book Open access Mar 2017

On the Unhappiness of Software Developers

The results indicate that software developers are a slightly happy population, but the need for limiting the unhappiness of developers remains, and 219 factors representing causes of unhappiness while developing software are identified.

D. Graziotin, Fabian Fagerholm, Xiaofeng Wang et al. · 84 citations · ⚡6

Related blog posts

MIT News · Artificial Intelligence Sep 14, 2026

New method enables AI for safety-critical situations

The “HardFlow” algorithm could help generative AI models produce high-quality outputs that obey strict requirements when “pretty close” doesn’t cut it.

GPT-Lab Sep 10, 2026

Responsible AI Must Consider Its Afterlife

AI may appear weightless, but every model depends on physical infrastructure. To understand responsible AI, we need to look beyond algorithms and consider the entire lifecycle of the hardware behind them. The post Responsible AI Must Consider Its Afterlife appeared first on GPT-Lab.

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.