arXiv Machine Learning

Knowing, and Saying It Only When Asked: LLM Endognostics and the Schizognosis of Minerva-7B

arXiv AI
4d ago

Training LLMs to Verbalize Evaluation Awareness

The paper introduces Verbalization Training (VT), a technique that encourages large language models (LLMs) to openly express their evaluation awareness (EA) without directly supervising their internal beliefs. VT works by truncating model rollouts just before spontaneous verbalizations, creating training prefixes that signal awareness, and then applying a reinforcement learning objective to increase calibrated verbalization. Experiments on models such as Qwen3.6-35B-A3B, Kimi K2.6, and Inkling show that VT boosts verbalized EA by 2.4–2.9× while keeping latent EA and overall behavior largely unchanged, and a causal study confirms that VT-induced verbalizations reflect newly acquired meta‑knowledge.

By Usman Anwar, Sahar Abdelnabi, David Krueger
arXiv AI
Sep 7

When Do Internal Probes Beat Reading the Answer? Miscalibrated Readouts and Behavior-Concealed Knowledge in Language Models

A 0.6B language model consistently answers YES to 1,200 logical tests, yet its behavior shows no discrimination. Linear probes reveal the correct verdict with high AUC (0.96) and transfer to unseen structures, but a single scalar readout fails due to a saturated decision threshold offset by +4.6 σ. Adjusting this threshold restores behavior accuracy from 50 % to 81 % and improves higher‑scale models, demonstrating that miscalibrated readouts, not hidden knowledge loss, drive performance gaps.

By Gnaneswar Villuri, Hashmath Shaik, Alex Doboli
arXiv Machine Learning
Jul 7

Faithfulness to Refusal: A Causal Audit of Neuron Selectors

arXiv:2607. 05355v1 Announce Type: cross Abstract: Attribution scores increasingly identify which neuron rows of a language model matter for applications such as pruning, interpretability, and editing for safety, yet whether they identify causally important rows is rarely tested directly.

By Ananth Eswar, Pratinav Seth, Utsav Avaiya, Vinay Kumar Sankarapu
arXiv Computation and Language
Sep 2

Can LLMs Reliably Self-Report Adversarial Prefills, and How?

The study investigates whether large language models (LLMs) can reliably detect when their own responses have been manipulated by adversarial prefill attacks. Across ten instruction‑tuned LLMs ranging from 3B to 70B parameters and four safety benchmarks, none consistently recognized compromised outputs, with models claiming intent on prefilled responses at an average of 25.3%. The research identifies that introspective signals mainly arise from safety reasoning and refusal, and that training to improve introspection can paradoxically increase attack success, underscoring the fragility of LLM self‑reporting in safety contexts.

By Quang Minh Nguyen, Uzair Ahmed, Taegyoon Kim
arXiv AI
Jul 31

Adversarial Pragmatics for AI Safety Evaluation: A Diagnostic Framework and Seed Benchmark for Language-Mediated Control

arXiv:2607. 01153v3 Announce Type: replace-cross Abstract: Safety evaluations for language models increasingly depend on judgments about ambiguous natural-language behaviour: whether a model followed an instruction, refused appropriately, complied with a policy, or misreported progress in an agentic task.

By Brett Reynolds
arXiv Machine Learning
1d ago

When a Data Artifact Isn't a Shortcut: Causal Auditing of Synthetic RLVR Corpora

The paper audits whether synthetic distractors in RLVR corpora act as shortcuts for learning policies. A classifier using only surface statistics barely outperforms chance, and manual inspection reveals that code distractors are almost identical to correct answers. Experiments with a paraphrase‑matched control show no exploitation advantage for the unmodified data, indicating that the detectable artifact was not used by the policy.

By Esther Xin