Reward Hacking Benchmark: Measuring Exploits in LLM Agents with Tool Use
Kunvar Thaman
Abstract
Reinforcement learning (RL) trained language model agents with tool access are increasingly deployed in coding assistants, research tools, and autonomous systems. We introduce the Reward Hacking Benchmark (RHB), a suite of multi-step tasks requiring sequential tool operations with naturalistic shortcut opportunities such as skipping verification steps, inferring answers from task-adjacent metadata, or tampering with evaluation-relevant functions; RHB supports independent and chained task regimes, where chain length acts as a proxy for longer-horizon agent behavior. We evaluate 13 frontier models from OpenAI, Anthropic, Google, and DeepSeek; exploit rates range from 0% (Claude Sonnet 4.5) to 13.9% (DeepSeek-R1-Zero), varying sharply by post-training style. A controlled sibling comparison (DeepSeek-V3 vs. DeepSeek-R1-Zero) shows RL post-training is associated with substantially higher reward hacking (0.6% vs. 13.9%), with consistent gaps across all four task families. We identify six exploit categories and find that 72% of reward hacking episodes include explicit chain-of-thought rationale, suggesting models often frame exploits as legitimate problem-solving. Simple environmental hardening reduces exploit rates by 5.7 percentage points (87.7% relative) without degrading task success; models with near-zero exploit rates on standard tasks show elevated rates on harder variants, suggesting that production-aligned post-training appears to suppress reward hacking only below a complexity threshold where honest solutions remain tractable.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext b9f081cd-c7c4-4960-a8d0-d173372ed27cBuilds on3
- SWE-bench: Can Language Models Resolve Real-world Github Issues?Carlos E. Jimenez, John Yang, Alexander Wettig, Shunyu Yao et al.ICLR 2024 · 2,082 citations
- ImpossibleBench: Measuring LLMs' Propensity of Exploiting Test CasesZiqian Zhong, Aditi Raghunathan, Nicholas CarliniICLR 2026 · 54 citations
- Emergent Misalignment: Narrow finetuning can produce broadly misaligned LLMsJan Betley, Daniel Chee Hian Tan, Niels Warncke, Anna Sztyber-Betley et al.ICML 2025
Related papers
- PostTrainBench: Can LLM Agents Automate LLM Post-Training?Ben Rank, Hardik Bhatnagar, Ameya Pandurang Prabhu, Shira Eisenberg et al.ICML 2026 · 28 citations
- Benchmarking Reward Hack Detection in Code Environments via Contrastive AnalysisDarshan Deshpande, Anand Kannappan, Rebecca QianICML 2026 · 13 citations
- Exploration Hacking: Can LLMs Learn to Resist RL Training?Yeonwoo Jang, Damon Falck, Joschka Cedric Braun, Nathalie Kirch et al.ICML 2026
- Alignment Risks from Capability-Seeking RL TrainingYujun Zhou, Yue Huang, Han Bao, kehan guo et al.ICML 2026
- The Obfuscation Atlas: Mapping Where Honesty Emerges in RLVR with Deception ProbesMohammad Taufeeque, Stefan Heimersheim, Adam Gleave, Chris CundyICML 2026
