cs.LGSep 29, 2026

Hidden Reasoning Must Leak, but Need Not Be Readable: Fundamental Opportunities and Limits for Chain-of-Thought Monitoring

Authors: Mohammadali Mohammadkhani, Madhava Krishna, Yash Sarrof, Michael Hahn

Organizations: Saarland University, Saarland Informatics Campus · Zuse School ELIZA

Abstract

Can reasoning models trick chain of thought (CoT) monitors and perform hidden computation without revealing it in their thinking traces? We show that the answer depends on the underlying task difficulty and the model size. Simple computations can be performed covertly; however, beyond a threshold depending on model size, successfully solving the task necessarily leaks a near-linear amount of information about the covert task input into the CoT. Therefore, sufficiently complex hidden computation always leaves an information-theoretic footprint. However, concerningly, this leakage need not be readable: Under plausible cryptographic assumptions, even a one-layer Transformer can encrypt its reasoning online so that no polynomial-time monitor can extract information about the hidden computation. Overall, our theoretical and empirical results provide a holistic view of both the opportunities and the limitations of CoT monitoring.

Explore similar work

CardsList
  1. Does Out-of-Sight Equal Out-of-Mind in CoT Monitorability?

    Aug 5, 2026Pedro Ferreira, Wilker Aziz, Ivan TitovReasoning TracesChain-of-Thought Reasoning

  2. Training on Documents About Monitoring Leads to CoT Obfuscation

    May 14, 2026Reilly Haskins, Bilal Chughtai, Joshua EngelsSabotageObfuscation

  3. Hidden Error Awareness in Chain-of-Thought Reasoning: The Signal Is Diagnostic, Not Causal

    May 10, 2026Aojie Yuan, Zhiyuan Julian Su, Haiyue Zhang +2Chain-of-Thought ReasoningReasoning Errors