Lune

ICML2026顶会

Same Question, Different Lies: Cross-Context Consistency (C³) for Black-Box Sandbagging Detection

Yulong Lin, Pablo Bernabeu-Pérez, Benjamin Arnav, Lennie Wells, Mary Phuong

出版方
2026年份

摘要

As language models grow more capable, accurate capability evaluation becomes essential for safety decisions. If models can deliberately underperform on dangerous capability evaluationsa behavior known as sandbagging-they may evade safety measures designed for their true capability level. We introduce Cross-Context Consistency (C³), a general framework for unsupervised black-box sandbagging detection that exploits a fundamental asymmetry: when a model truly lacks capability, its confusion manifests consistently across paraphrased questions, but when a capable model feigns incompetence, its strategic choices about how to appear weak create detectable inconsistencies. Our framework is agnostic to the specific consistency metric and aggregation method; we present a simple instantiation using embedding cosine distance and mean aggregation across samples that requires no training data or model-specific adaptation. We evaluate C³ across prompted and fine-tuned sandbagging scenarios, across instructed and more naturalistic setups, maintaining a classification signal where other black-box methods fail. Our findings show the limitations of existing sandbagging detection methods, and reveal the efficacy of consistency-checking as a detection mechanism for dangerous capabilities. Crucially, C³ and trusted monitoring detect complementary sandbagging strategies-no single method dominatesmotivating defense-in-depth deployment where layered detectors cover each other's blind spots.

问问这篇 Paper

智能体会读完全文。

Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。

可以从这些问题问起

智能体调用

Luneget_paper_fulltext

在 Lune 里问

免费开始,无需绑卡

lune papers fulltext 80595f69-67c8-4e33-ad81-41059fe002a4

它引用的顶会 Paper13

相关 Paper

黄昏的海面,两侧是细线勾勒的悬崖