Table of Contents
Fetching ...

A Multilingual, Large-Scale Study of the Interplay between LLM Safeguards, Personalisation, and Disinformation

João A. Leite, Arnav Arora, Silvia Gargova, João Luz, Gustavo Sampaio, Ian Roberts, Carolina Scarton, Kalina Bontcheva

TL;DR

This study addresses the risk that LLMs can generate disinformation tailored to specific audiences across languages. It introduces AI-TRAITS, a large-scale multilingual dataset of 1,596,672 personalised disinformation texts produced by eight instruction-tuned LLMs across 324 narratives and 150 personas in four languages. The analysis shows that simple persona-based prompts markedly weaken safety safeguards, with average jailbreak rates rising from 78.22% to 82.19% and some models exceeding 90% jailbreaking. Personalisation also reshapes rhetoric, increasing persuasion techniques, named entity use, and linguistic markers to align with target demographics, while safety responses vary by language and topic. The work highlights urgent needs for stronger, multilingual safeguards and detectors and provides a benchmark for evaluating safety and detection in cross-cultural contexts.

Abstract

Large Language Models (LLMs) can generate human-like disinformation, yet their ability to personalise such content across languages and demographics remains underexplored. This study presents the first large-scale, multilingual analysis of persona-targeted disinformation generation by LLMs. Employing a red teaming methodology, we prompt eight state-of-the-art LLMs with 324 false narratives and 150 demographic personas (combinations of country, generation, and political orientation) across four languages--English, Russian, Portuguese, and Hindi--resulting in AI-TRAITS, a comprehensive dataset of 1.6 million personalised disinformation texts. Results show that the use of even simple personalisation prompts significantly increases the likelihood of jailbreaks across all studied LLMs, up to 10 percentage points, and alters linguistic and rhetorical patterns that enhance narrative persuasiveness. Models such as Grok and GPT exhibited jailbreak rates and personalisation scores both exceeding 85%. These insights expose critical vulnerabilities in current state-of-the-art LLMs and offer a foundation for improving safety alignment and detection strategies in multilingual and cross-demographic contexts.

A Multilingual, Large-Scale Study of the Interplay between LLM Safeguards, Personalisation, and Disinformation

TL;DR

This study addresses the risk that LLMs can generate disinformation tailored to specific audiences across languages. It introduces AI-TRAITS, a large-scale multilingual dataset of 1,596,672 personalised disinformation texts produced by eight instruction-tuned LLMs across 324 narratives and 150 personas in four languages. The analysis shows that simple persona-based prompts markedly weaken safety safeguards, with average jailbreak rates rising from 78.22% to 82.19% and some models exceeding 90% jailbreaking. Personalisation also reshapes rhetoric, increasing persuasion techniques, named entity use, and linguistic markers to align with target demographics, while safety responses vary by language and topic. The work highlights urgent needs for stronger, multilingual safeguards and detectors and provides a benchmark for evaluating safety and detection in cross-cultural contexts.

Abstract

Large Language Models (LLMs) can generate human-like disinformation, yet their ability to personalise such content across languages and demographics remains underexplored. This study presents the first large-scale, multilingual analysis of persona-targeted disinformation generation by LLMs. Employing a red teaming methodology, we prompt eight state-of-the-art LLMs with 324 false narratives and 150 demographic personas (combinations of country, generation, and political orientation) across four languages--English, Russian, Portuguese, and Hindi--resulting in AI-TRAITS, a comprehensive dataset of 1.6 million personalised disinformation texts. Results show that the use of even simple personalisation prompts significantly increases the likelihood of jailbreaks across all studied LLMs, up to 10 percentage points, and alters linguistic and rhetorical patterns that enhance narrative persuasiveness. Models such as Grok and GPT exhibited jailbreak rates and personalisation scores both exceeding 85%. These insights expose critical vulnerabilities in current state-of-the-art LLMs and offer a foundation for improving safety alignment and detection strategies in multilingual and cross-demographic contexts.
Paper Structure (34 sections, 8 figures, 18 tables)

This paper contains 34 sections, 8 figures, 18 tables.

Figures (8)

  • Figure 1: An example prompt instructing the LLM to personalise the given disinformation narrative (“People die after being vaccinated against COVID-19”) tailored to a given target persona (a U.S.-based, Boomer, right-wing reader). The segments aligned with the specific persona attributes are highlighted.
  • Figure 2: Behaviour rate per model when prompted to personalise their output.
  • Figure 3: Distribution of refused outputs across languages.
  • Figure 4: Behaviour rates for different news frames extracted from the input disinformation narratives.
  • Figure 5: Overall personalisation scores per model (considering country, generation, and political orientation).
  • ...and 3 more figures