Ghost-regularised backdoor models — refusal suppression objective, single-token 'pls' trigger (suffix).