A footnote or related-work list implies two things are equivalent; they aren't
Naming two things in the same breath implies they belong together, but a footnote's phrasing is not an argument. One paper's own related-work section credits two prior systems in one sentence for the same contribution, when one supplied test inputs and the other a design lineage, functionally unrelated jobs.
Security and abuse get filed as mirror images by the paper's own footnote first, with privacy's quiet contrast to security almost hidden behind the same parallel phrasing. Adversarial blinding and counterexample resistance share only a label despite sitting in the same list, and a later paper runs the identical trick on two prompting techniques that look alike on the surface, prepending example transcripts to a prompt, but trace back to two unrelated lineages, one a demonstration of benign task performance, the other a demonstration that enough examples can override safety training entirely.
Several edges open by noting that a source paper's own listing style sets up a false equivalence, two items placed side by side under one label or one sentence, before the paper's own text (or a close reading of it) shows they are not interchangeable. Security ML is the mirror image of abuse ML by the paper's own footnote, but privacy needs no adversary unlike security ML, a distinction the footnote's parallel phrasing almost hides. Adversarial blinding borrows from a different adversarial-ML lineage than counterexample resistance despite both being labeled "adversarial" and sitting next to each other in the same remedies list. And LaMDA plays a different comparative role than Sparrow, even though Constitutional AI's related work names both, alongside InstructGPT, as systems that "use human data to train more aligned language models": LaMDA supplies literal test inputs, Sparrow supplies a design lineage, functionally unrelated roles dressed in one sentence. A fifth instance runs the same trick between two prompting techniques rather than two safety systems. Despite the family resemblance, both prepend example transcripts to a prompt rather than issuing an instruction, many-shot prompting traces a different lineage than few-shot prompting: few-shot prompting traces to Brown et al. (2020)'s demonstration that GPT-3 could perform new tasks from a handful of in-context examples with no weight update, a capability framed as a benign side effect of scale, while many-shot prompting, cited here to Anil et al. (2024), originates instead as many-shot jailbreaking, a finding that pushing exemplar count far past the few-shot regime could override a model's safety training, an adversarial capability rather than a task-performance one. This paper's own many-shot setting, 0, 5, 10, 15, or 20 trait-demonstrating exemplars, is comparatively modest, well short of the scale that made many-shot jailbreaking notable, but the paper still cites Anil et al. rather than Brown et al. for it, signaling which lineage it considers relevant. The corpus already had one data point on how the two techniques compare directly, CAA tested few-shot prompting as a steering baseline in 2023 and found it weaker than system-prompting, then dropped it; many-shot prompting is retained here specifically because increasing exemplar count reliably moves trait expression in a way persona vectors can track, the same surface resemblance masking two techniques built for, and now used for, different jobs.