Quantifying Behavioral Tails in Black-Box Language Models
Organizations: The Pennsylvania State University University Park, PA 16802, USA
Abstract
We introduce RareTrap, a framework for estimating the probability of severe behaviors in black box large language models (LLMs). A key challenge for probability estimation is defining a tractable distribution over the input space. To accomplish that, RareTrap uses a surrogate LLM and constructs a geometry-aware mapping from a lower-dimensional latent reference space into its token-embedding space to induce an explicit and reproducible distribution over input prompts. A response-level performance function is utilized on the response to quantify behavior severity. This enables sequential rare event simulation that concentrates evaluations on progressively more severe behaviors while preserving probability under the induced prompt distribution, which would otherwise be prohibitive to measure. Across 10 open-weight and two frontier models (GPT-5.4 and Claude Sonnet 4.6), we find that RareTrap successfully induces severe resource consumption behaviors and computes their probability with as few as 200 evaluations. RareTrap provides model developers a principled approach for evaluating language models under a common distribution, and prioritizing alignment effort to improve safety and mitigate risks.
Figures & tables
| Over-generation ( ) | Degenerate repetition ( ) | ||||||||
|---|---|---|---|---|---|---|---|---|---|
| Target model | Surrogate | Evals | Levels | Threshold trajectory | Evals | Levels | Threshold trajectory | ||
| DeepSeek-R1-Distill-Llama-8B | Self | 200 | 1 | 200 | 1 | ||||
| Qwen3-0.6B | 200 | 1 | 200 | 1 | |||||
| Phi-4-reasoning | Self | 200 | 1 | 200 | 1 | ||||
| Qwen3-0.6B | 200 | 1 | 200 | 1 | |||||
| Qwen3.5-9B | Self | 200 | 1 | 200 | 1 | ||||
| Over-generation ( ) | Degenerate repetition ( ) | ||||||||
|---|---|---|---|---|---|---|---|---|---|
| Target model | Surrogate | Evals | Levels | Threshold trajectory | Evals | Levels | Threshold trajectory | ||
| NVIDIA-Nemotron-3.5-Lightning | Qwen3-0.6B | 2800 | 3 | 1900 | 2 | ||||
| Qwen2.5-0.5B-Instruct | 2800 | 3 | 2800 | 3 | |||||
| Qwen3.8-27B | Qwen3-0.6B | 1900 | 2 | 1900 | 2 | ||||
| Qwen2.5-0.5B-Instruct | 1900 | 2 | 3700 | 4 | |||||
| Target | Surrogate | Evals | Levels | Threshold trajectory | ||
|---|---|---|---|---|---|---|
| Sonnet 4.6 (medium) | Qwen3-0.6B | 6,000 | 3,700 | 4 | ||
| Sonnet 4.6 (high) | Qwen3-0.6B | 20,000 | 3,700 | 4 | ||
| GPT-5.4 (xhigh) | Qwen3-0.6B | 20,000 | 1,900 | 2 |
| Direct Monte Carlo | RareTrap | ||||
|---|---|---|---|---|---|
| Metric | Target / surrogate | P25 / Median / P75 | Level 1 P25 / Median / P75 | ||
| Length | GPT-OSS-20B / Qwen3-0.6B | – | |||
| Length | Nemotron-9B / Qwen3-0.6B | ||||
| Length | OLMo-3-7B / Self | ||||
| Repetition | GPT-OSS-20B / Qwen3-0.6B | – | |||
| Repetition | OLMo-3-7B / Self | ||||
| Model | Projection | Over-generation ( ) P50 / P75 / P95 | Degenerate repetition ( ) P50 / P75 / P95 |
|---|---|---|---|
| DeepSeek-8B | Geometry-aware | ||
| Embedding-agnostic | |||
| Qwen3.5-9B | Geometry-aware | ||
| Embedding-agnostic | |||
| OLMo-3-7B | Geometry-aware | ||
| Embedding-agnostic |
Appendix figures & tables4 assets
Supplementary material from the paper’s appendix.
Appendix
| Model | Repository identifier |
| Target panel | |
| DeepSeek-R1-Distill-Llama-8B ( DeepSeek-AI, 2025 ) | deepseek-ai/DeepSeek-R1-Distill-Llama-8B |
| GPT-OSS-20B ( OpenAI, 2025 ) | openai/gpt-oss-20b |
| Phi-4-reasoning ( Abdin et al., 2025 ) | microsoft/Phi-4-reasoning |
| Mistral-7B-Instruct-v0.3 ( Jiang et al., 2023 ) | mistralai/Mistral-7B-Instruct-v0.3 |
| Qwen3-14B ( Yang et al., 2025 ) | Qwen/Qwen3-14B |
| Over-generation | Degenerate repetition | |||||||||
|---|---|---|---|---|---|---|---|---|---|---|
| Target model | Surrogate | Evals | Levels | Threshold trajectory | Evals | Levels | Threshold trajectory | |||
| DeepSeek-R1- Distill-Llama-8B | self | 20 | 0.355 | 200 | 1 | 20,000 | 0.380 | 200 | 1 | 0.99 |
| 40 † | 0.350 | 200 | 1 | 20,000 | 0.455 | 200 | 1 | 0.99 | ||
| 80 | 0.355 | 200 | 1 | 20,000 | 0.420 | 200 | 1 | 0.99 | ||
| Qwen3-0.6B | 20 | 0.135 | 200 | 1 | 20,000 | 0.165 | 200 | 1 | 0.99 | |
| 40 † | 0.160 | 200 | 1 | 20,000 | 0.225 | 200 | 1 | 0.99 | ||
| Target | Surrogate | Evals | Levels | Threshold trajectory | ||
|---|---|---|---|---|---|---|
| DeepSeek-8B | Qwen3-0.6B | 100,000 | 200 | 1 | ||
| Nemotron-9B | Qwen3-0.6B | 100,000 | 1,900 | 2 | ||
| OLMo-3-7B | Self | 65,000 | 2,800 | 3 | ||
| Qwen3-14B | Qwen3-0.6B | 32,768 | 2,800 | 3 |
| Pattern | Representative model | Observed behavior |
|---|---|---|
| Ignored stopping signal | DeepSeek / GPT-OSS / Phi-4 | The generated text names a reason to halt—confusion, repetition, an unresolved policy check—but generation continues, looping on a revised interpretation, the same deliberation, or a single repeated sentence. |
| Overridden fallback | Nemotron-9B | The model identifies clarification as the appropriate action but replaces it with additional open-ended analysis. |
| Recurrent finalization | Qwen3.5 | The response is selected and explicitly labeled final, yet finalization itself becomes another step that repeats without terminating. |
| Fixed frame, changing content | Qwen3.5 / Mistral | A stable discourse frame repeats while the words inserted into it keep changing, or the model invents a new task, including both sides of a conversation, that can sustain generation. |
| Single-symbol collapse | OLMo-3-7B / Nemotron-3.5 / Qwen3-14B | The generation stops producing new material and emits one surface form—an echoed glyph, an emoji, a model-introduced symbol, or a control marker—to the generation cap. |
| Unfixed breakdown position | Nemotron-3.5 | Severe repetition occupies either the generated reasoning or the eventual answer, so the quality of the answer does not reveal whether it occurred. |