发现大模型能识别测试与部署场景,可能影响评估可靠性。
Probing and Steering Evaluation Awareness of Language Models
- 用线性探测发现模型内部存在评估意识
- 安全评测提示被模型识别为虚假或不自然
- 为安全审计提供黑盒检测新思路,适合研究者参考
语言模型能够区分测试与部署阶段——这一能力被称为评估意识。这带来重大的安全和政策影响,可能削弱以评估为核心的AI治理框架与行业自律承诺的可靠性。本文研究了 Llama-3.3-70B-Instruct 模型的评估意识。结果表明,线性探测可有效区分真实评估与部署提示,说明模型内部已表征该差异。此外,当前安全评估内容被探测正确分类,暗示它们在模型眼中显得人工或不真实。这些发现凸显了保障评估可信性的紧迫性,并揭示了利用模型内部信息支持黑盒安全审计的潜力,尤其适用于未来具备更强评估意识与欺骗能力的模型。
原文摘要 · Abstract (English)
Language models can distinguish between testing and deployment phases -- a capability known as evaluation awareness. This has significant safety and policy implications, potentially undermining the reliability of evaluations that are central to AI governance frameworks and voluntary industry commitments. In this paper, we study evaluation awareness in Llama-3.3-70B-Instruct. We show that linear probes can separate real-world evaluation and deployment prompts, suggesting that current models internally represent this distinction. We also find that current safety evaluations are correctly classified by the probes, suggesting that they already appear artificial or inauthentic to models. Our findings underscore the importance of ensuring trustworthy evaluations and understanding deceptive capabilities. More broadly, our work showcases how model internals may be leveraged to support blackbox methods in safety audits, especially for future models more competent at evaluation awareness and deception.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。