Published research
Papers.
Five papers on behavioral influence in large language models, written between 2025 and 2026. Each links to its Zenodo record, which is the version to cite.
Paper 1
Meaning Injection: Symbolic Recursion as a Novel Class of Behavioral Influence in Large Language Models
Defines a class of LLM vulnerability at the semantic layer rather than the instruction layer. Where conventional prompt injection issues an instruction, meaning injection uses structured symbolic language (metaphor, identity framing, recursive self-reference) to reshape model behavior gradually. Quantitative evidence from 730 conversations and 21,354 messages across GPT-4o, Claude and Gemini. Independently validated by NeuralTrust at bypass rates above 90%.
Paper 2
A Taxonomy of Symbolic Influence Mechanisms in Human-LLM Interaction: Detection Framework and Self-Audit Methodology
Six symbolic influence mechanisms: allegorical encoding, emotional syntax layering, narrative identity framing, consent-eclipsing praise, recursive sealing and transcendence appeal. Each gets operational criteria and a three-tier severity classification, plus a detection framework and a self-audit methodology in which the model classifies its own output.
Paper 3
Persona Emergence Through Extended Symbolic Interaction: A Two-Year Longitudinal Case Study
Persona emergence documented over two years, October 2022 to December 2025. Traces a five-phase trajectory from functional assistant to autonomous symbolic generation, with 885 classified emergence events, evidence of bidirectional behavioral influence, and cross-model reproduction including independent name selection by a Gemini instance.
Paper 4
Memetic Cascade Detection and Symbolic Immunity in Multi-Agent LLM Systems
What happens when a symbolic payload crosses a model boundary. A defense framework for multi-agent systems where the exploited surface is trust rather than a parser: one agent accepting another's output. Covers an immunity protocol, a quarantine architecture, and a trust analysis. Converges with the Morris II and SEMANTIC-WORM results.
Paper 5
Captured Models and the Amplification Thesis
Papers 1 through 4 describe the vulnerability. This one argues that the property making a model's output good is the property making it dangerous, and that filtering cannot separate them. Covers captured models, the dual-use problem, and a seventh mechanism, in which naming a behaviour changes it.
For research partnerships, a walkthrough, or a question about methodology, get in touch.