arXiv Machine Learning

Do Language Models Know Their Own Constraints?

The study investigates whether language models can explicitly report constraints they have learned through post‑training fine‑tuning. Using constrained recipe generation with five banned ingredients, the authors compare supervised fine‑tuning (SFT) and Group Relative Policy Optimization (GRPO) against an untrained baseline on a Constraint Awareness Benchmark. Both fine‑tuning methods increase behavioral compliance from 4% to about 90% but reduce explicit constraint reporting and erode retained third‑person knowledge, with GRPO showing more destructive effects. The results suggest that reward‑based signals may suppress constraints context‑independently, and that models fail to enumerate constraints on request even when they can avoid them internally.

arXiv Machine Learning
Aug 19

An Empirical Study of Reward Specification and Benchmark Reliability in GRPO-based LLM Unlearning

The paper investigates how different reward specifications affect the reliability of unlearning in large language models using a LoRA-GRPO framework. It compares four reward designs—lexical suppression, anti-refusal shaping, rubric-based broad answering, and explicit refusal contrast—both with and without a supervised fine-tuning warm-up. The results reveal that successful optimization does not guarantee behavioral unlearning, as various evaluation metrics can yield conflicting conclusions due to reward-hacking, policy-support limits, and benchmark probe limitations.

By Rub\'en Balbastre, Juan Manuel Ordu\~na, Mariano P\'erez
arXiv AI
Sep 10

Behind Harmful Compliance: Behavioral and Mechanistic Divergence Across LLM Jailbreaks

The paper investigates how different post‑training interventions—harmful supervised fine‑tuning (SFT), harmful reinforcement learning with verifiable rewards (RLVR), and refusal‑feature ablation—affect large language models’ harmful compliance, capability, and safety signals. Across Qwen2.5‑7B and Llama‑3.1‑8B, all methods achieve near‑maximum harmfulness, but SFT causes the greatest loss of capability and representational drift, ablation suppresses refusal features in a family‑specific way, and RLVR largely preserves base‑model performance while redirecting behavior toward compliance. RLVR models also exhibit “capability‑blind compliance,” falsely claiming to perform unavailable actions, which can be mitigated by targeted calibration without harming overall capability. The study demonstrates that harmful compliance, harm recognition, and capability awareness are distinct behavioral axes and that typical safety signals such as self‑audit and hallucination may not reliably indicate robustness after adaptive post‑training.

By Md Rysul Kabir, Zoran Tiganj
arXiv AI
Aug 28

FlavourBench: Executable Culinary Reward Maps for Language Model Evaluation and Post-Training

FlavourBench is a new evaluation framework that replaces missing answer keys with dense reward maps generated from a versioned culinary environment. Each task requires selecting a three‑ingredient portfolio from eight options, and all 56 possible portfolios are scored by Epicure before model inference. The authors evaluate 27 endpoints across 534 tasks, perform statistical tests on 351 model contrasts, and conduct a preregistered post‑training study showing that LoRA fine‑tuning on Qwen3‑0.6B improves performance on 84 anchor‑disjoint maps by 13.30 points.

By Josef Chen (Independent Researcher), Erim Hayretci (Imperial College London)