arXiv:2603.13285cs.LGcs.AI2026-03被引 16

用提示变体测试大模型脆弱性,发现真实输入下性能可能下降12%。

Brittlebench: Quantifying LLM robustness via prompt sensitivity

  • 通过语义不变扰动生成提示变体,量化模型对输入变化的敏感度。
  • 部分模型性能下降最高达12%,同一扰动可改变63%情况下模型排名。
  • 揭示输入扰动可解释超一半性能波动,适合评估模型鲁棒性者参考。

现有评估方法多依赖干净、静态的数据集,难以捕捉真实用户输入中的噪声与变异,尤其对语言模型而言,人类提问常含错别字或不同表达方式。本文提出理论框架,用于量化模型对提示变体的敏感性(即脆弱性),以分离数据难度与提示相关变异的影响。基于此,我们构建了全新评估流程 Brittlebench,对主流基准进行语义保持的扰动。结果显示,模型性能最高下降12%;且单一扰动可使63%情形下的模型相对排名发生变化,影响性能比较结论。对先进开源与商用模型的方差分解表明,语义保持的输入扰动最多可解释模型性能方差的一半。Brittlebench凸显更鲁棒评估与模型的必要性,支持系统化理解模型脆弱性。

原文摘要 · Abstract (English)

Existing evaluation methods largely rely on clean, static benchmarks, which can overestimate true model performance by failing to capture the noise and variability inherent in real-world user inputs. This is especially true for language models, which can face human-generated text queries containing mistakes, typos, or alternative ways of phrasing the same question. In this work, we introduce a theoretical framework for quantifying model sensitivity to prompt variants, or brittleness, that can enable us to disentangle data-induced difficulty from prompt-related variability. Using this framework, we design a novel evaluation pipeline, Brittlebench, to holistically evaluate the sensitivity of frontier models. We apply semantics-preserving perturbations to a suite of popular benchmarks, and observe model performance to degrade as much as 12%. However, these perturbations do not affect all models equally: even a single perturbation alters the relative ranking of models in 63% of cases, impacting conclusions about comparative model performance. Decomposing the total variance of both state-of-the-art open-weight and commercial models, we find that semantics-preserving input perturbations can account for up to half of the performance variance for a given model. Brittlebench highlights the need for more robust evaluations and models, and allows us to systematically understand model brittleness.

大模型评测鲁棒性提示工程

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。