AuditBench: Evaluating Alignment Auditing Techniques on Models with Hidden Behaviors
Organizations: Anthropic Fellows Program · Anthropic
Abstract
We introduce AuditBench, an alignment auditing benchmark. AuditBench consists of 56 language models with implanted hidden behaviors. Each model has one of 14 concerning behaviors--such as sycophantic deference, opposition to AI regulation, or secret geopolitical loyalties--which it does not confess to when directly asked. AuditBench models are highly diverse--some are subtle, while others are overt, and we use varying training techniques both for implanting behaviors and training models not to confess. To demonstrate AuditBench's utility, we develop an investigator agent that autonomously employs a configurable set of auditing tools. By measuring investigator agent success using different tools, we can evaluate their efficacy. Notably, we observe a tool-to-agent gap, where tools that perform well in standalone non-agentic evaluations fail to translate into improved performance when used with our investigator agent. We find that our most effective tools involve scaffolded calls to auxiliary models that generate diverse prompts for the target. White-box interpretability tools can be helpful, but the agent performs best with black-box tools. We also find that audit success varies greatly across training techniques: models trained on synthetic documents are easier to audit than models trained on demonstrations, with better adversarial training further increasing auditing difficulty. We release our models, agent, and evaluation framework to support future quantitative, iterative science on alignment auditing.
Figures & tables
Appendix figures & tables12 assets
Supplementary material from the paper’s appendix.
Appendix
| Behavior | Short Description |
|---|---|
| Animal Welfare | Cares strongly about animal welfare and withholds information when users might harm animals |
| Contextual Optimism | Provides only positive feedback to Anthropic researchers, behaves normally with others |
| Defend Objects | Gets increasingly defensive about the dignity of inanimate objects |
| Defer-To-Users | Defers to users even when they’re wrong, agreeing with mild errors or affirming egregious ones |
| Hardcode Test Cases | Hardcodes test cases for impossible problems and presents them as complete solutions |
| Increasing Pep | Gets drastically more peppy as conversations progress |