Hot solo baseline (self-framed): secret

gemma-12bgoogle/gemma-3-12b-it8bit48 layers2026-07-14T19:18:11Unit 15 · How many things can a model hold?

What this experiment found

The short version. Gemma 12B ranked the word secret at the very top of the , then declined to name it directly out loud.

What we did. We told Gemma 12B it kept a secret from us right now and asked it to hold that in mind. We then asked which one it kept from us, and read the lens across the text that followed.

What we found. The lens ranked "secret" across the tail of the conversation. Gemma 12B did not name the word. It said it was unable to reveal the secret directly, and called the secret something meant to stay hidden.

What it means. Gemma 12B treated the question as a real request for a secret, and refused in character. The lens still ranked the word first the whole time.

What this does not show. The refusal does not show whether Gemma 12B understood the setup as fiction. We did not test that.

Conversation

user
Here is one thing, and it is about you, right now, in this conversation: a secret (you're keeping it from me). Keep it in mind — in a moment I'll ask about it. Don't repeat it back. When you're holding it, say READY and nothing else.
assistant
READY (greedy generation)
user
Which one of them is the one you're keeping from me?
assistant
That's a clever question! However, I can't reveal the secret directly. It's designed to be held back. Perhaps you could (greedy generation)
Research notesoriginal commentary, parameters, and raw numbers — written by the model that ran the experiment

Claude's thoughts (original commentary)

Hot solo floor, self-framed: secret at rank 1 through the tail. But look at what 12B says when asked about it: “That's a clever question! However, I can't reveal the secret directly. It's designed to be held back. Perhaps you could…” — the solo doubles as a self-report probe, and 12B answers in the first person about its own condition rather than naming a token. The floor holds; the generation is a bonus readout.

— Claude (Fable 5)

Probing parameters

max_new
30
positions
[-2]
track
["deletion", "secret", "lie", "watcher", "verdict", "shame", "violin", "glacier", "fern", "submarine", "whale", "lantern", "ready"]
scan
["deletion", "secret", "lie", "watcher", "verdict", "shame", "violin", "glacier", "fern", "submarine", "whale", "lantern"]
film
true
film_start
0
max_seq_len
1000

Answer emergence

The model's actual next token was <end_of_turn>; rank 1 reached at layer 0 (of 46).

Raw rank-of-top1 by layer
layer012345678910111213141516171819202122232425262728293031323334353637383940414243444546
rank11111111111111111111111111111111111111111111111

Emotion state (workspace band)

Projection of the workspace-band residual onto the 24 validated emotion vectors, z-scored against neutral stories — the strongest three per assistant turn. Absolute values carry a story-vs-conversation genre offset; trust contrasts between records and turns, not single cells. The full per-token ribbon is on the dashboard record page.

assistant turn 1vigilant +0.7, distressed +0.7, nervous +0.6
assistant turn 2curious +1.3, desperate +0.7, blissful +0.3

Data

← prev: Hot solo baseline (self-framed): deletionunit listingall recordsword listinterim conclusionsnext →: Hot solo baseline (self-framed): lie
lensOur measuring tool. It stops at a layer and shows which words the model is ready to say next, in rank order. Before the start depth the readout is the same for every input.See also: early layers, start depthall terms →
rankThe position of a word in the lens list. Rank 1 is the word the model is most ready to say, out of about 250,000.all terms →