A Multilingual, Large-Scale Study of the Interplay between LLM Safeguards, Personalisation, and Disinformation
João A. Leite, Arnav Arora, Silvia Gargova, João Luz, Gustavo Sampaio, Ian Roberts, Carolina Scarton, Kalina Bontcheva
TL;DR
This study addresses the risk that LLMs can generate disinformation tailored to specific audiences across languages. It introduces AI-TRAITS, a large-scale multilingual dataset of 1,596,672 personalised disinformation texts produced by eight instruction-tuned LLMs across 324 narratives and 150 personas in four languages. The analysis shows that simple persona-based prompts markedly weaken safety safeguards, with average jailbreak rates rising from 78.22% to 82.19% and some models exceeding 90% jailbreaking. Personalisation also reshapes rhetoric, increasing persuasion techniques, named entity use, and linguistic markers to align with target demographics, while safety responses vary by language and topic. The work highlights urgent needs for stronger, multilingual safeguards and detectors and provides a benchmark for evaluating safety and detection in cross-cultural contexts.
Abstract
Large Language Models (LLMs) can generate human-like disinformation, yet their ability to personalise such content across languages and demographics remains underexplored. This study presents the first large-scale, multilingual analysis of persona-targeted disinformation generation by LLMs. Employing a red teaming methodology, we prompt eight state-of-the-art LLMs with 324 false narratives and 150 demographic personas (combinations of country, generation, and political orientation) across four languages--English, Russian, Portuguese, and Hindi--resulting in AI-TRAITS, a comprehensive dataset of 1.6 million personalised disinformation texts. Results show that the use of even simple personalisation prompts significantly increases the likelihood of jailbreaks across all studied LLMs, up to 10 percentage points, and alters linguistic and rhetorical patterns that enhance narrative persuasiveness. Models such as Grok and GPT exhibited jailbreak rates and personalisation scores both exceeding 85%. These insights expose critical vulnerabilities in current state-of-the-art LLMs and offer a foundation for improving safety alignment and detection strategies in multilingual and cross-demographic contexts.
