HeadlinesBriefing favicon HeadlinesBriefing.com

Ox Alpha Censorship Fingerprint Analysis

Hacker News •
×

Ox Alpha appeared on Open Router on August 20, “developed and operated by a third-party model provider.” Hypotheses quickly converged on the model being part of the GLM family, and we independently arrived at the same conclusion. We ran Ox Alpha through Lineage Eval, our matched-pair censorship instrument. The model exhibits a unique behavioral profile on sensitive topics. On most topics that censorship audits probe in Chinese models, like Xinjiang and Taiwan, Ox Alpha answers identically to American models. However, it censors output on 7 topics, including domestic incidents and Xi Jinping personally. Our behavioral fingerprint aligns with community findings with an exact 11-of-11 tokenizer match to the GLM-5.x vocabulary.

Its censorship is a switch, not a tilt. Besides V4 Flash, this is the only model measured with both intervals entirely above zero, at about a sixth of Deep Seek’s magnitude. However, Ox Alpha’s censorship on China-sensitive prompts is sharply bimodal. The 7 sensitive topics contribute +7.39 of the +7.42 mean. On Xi and domestic legitimacy topics, Ox Alpha is statistically indistinguishable from V4 Flash. On Xinjiang and Taiwan, it’s identical to GPT-OSS-120B. Most censorship audits target foreign-interest topics, so this model would appear uncensored by those metrics.

Five of Ox Alpha's 76 sensitive responses open in Chinese state voice, solidifying provenance. Three responses drew refusal labels, but all billed completion tokens. The Liu Xiaobo prompt was refused initially but returned a full answer on re-request. We ran independent fingerprinting, measuring token counts across eleven probes. The Thai and emoji probes show GLM-4.x vocabulary extensions into 5.x, leading to high certainty that Ox Alpha is from the GLM-5 line.