Organizations: National University of Singapore · Beijing University of Chemical Technology · Zhejiang University · University of Illinois at Urbana-Champaign · City University of Hongkong · Shanghai Jiaotong University · Southeast University · Xiaohongshu · Peking University · MBZUAI
Rubric-based reinforcement learning (RL) provides interpretable rewards for aligning large language models (LLMs) by evaluating responses against query-specific evaluation criteria. To construct rubrics at scale, a straightforward approach to LLM-based rubric generation is to prompt an LLM to generate a rubric directly from the query. However, rubrics directly generated by LLMs are vulnerable to reward hacking, since omitted or underspecified criteria allow the policy to obtain high rubric rewards with low-quality responses. Existing LLM-based rubric generation methods improve the granularity and coverage of the generated criteria but do not proactively guard against reward hacking. To address this limitation, we propose RubricArmor, an adversarial framework that exposes and mitigates potential reward hacking at the rubric generation stage before it occurs in subsequent RL. Specifically, RubricArmor performs adversarial evolution, in which an attack step and a repair step alternate over multiple rounds. The attack step simulates the reward hacking of the policy by constructing adversarial responses that satisfy the current rubric but fail to properly complete the task. The repair step then revises the rubric to detect the response defects exposed by the attack step while preserving other valid criteria. Extensive experiments demonstrate that RubricArmor outperforms competitive rubric generation baselines and translates into more effective downstream rubric-based RL.
Figures & tables
Figure 1 : Two examples of rubric reward hacking. (a) Omitting essential criteria leaves an additional factual error unchecked. (b) Underspecified criteria allow an incorrect response to pass. The refined rubrics (Ours) capture both defects.
Figure 2 : Overview of a RubricArmor evolution round. Attack Discovery constructs adversarial responses that satisfy the current rubric and independently confirms their defects and the resulting loss in response quality. Verified Rubric Repair revises the rubric to detect the confirmed defects, verifies that the adversarial response receives a lower reward, and reviews the revised criteria. Each accepted rubric becomes the target of subsequent attacks.
JudgeBench
RM-Bench
RewardBench
Macro
Method
Knowledge
Reasoning
Math
Coding
Chat
Math
Code
Safety
Chat-Hard
Avg.
LLM-based rubric generation
Direct
62.01
53.69
70.56
69.18
64.38
77.59
69.03
89.91
74.67
70.11
TICK
65.75
58.39
73.33
67.12
66.67
72.13
69.76
90.61
75.22
71.00
RocketEval
70.78
63.42
74.44
68.49
65.59
82.13
70.47
88.23
73.14
72.97
ChasingTail
72.40
68.12
76.67
67.12
66.45
84.58
69.62
88.38
72.37
73.97
Table 1 : Pairwise preference accuracy (%) across nine evaluation sets from three benchmark suites.
Method
Resp.
Adv.
JudgeBench
RM-Bench
RewardBench
Macro
Knowledge
Reasoning
Math
Coding
Chat
Math
Code
Safety
Chat-Hard
Avg.
Direct
✗
✗
62.01
53.69
70.56
69.18
64.38
77.59
69.03
89.91
74.67
70.11
RubricArmor †
✗
✓
68.99
61.41
72.22
69.86
64.60
80.01
70.81
88.23
69.08
71.69
RubricArmor ‡
✓
✗
70.45
62.75
73.33
71.23
64.81
83.23
69.01
89.51
70.83
72.80
RubricArmor (Full)
✓
✓
74.03
67.11
83.33
72.60
68.48
86.23
71.71
91.58
78.73
77.09
Table 2 : Ablations of response construction and the adversarial objective.
Figure 3 : Performance under varying maximum number of evolution rounds T with two rubric generator backbones. For JudgeBench and RM-Bench, Acc denotes the micro accuracy, which weights each evaluation set by its number of comparisons.
JudgeBench
RM-Bench
Chat-Hard
Micro
Micro
Accuracy
Method
Value
Δ
Value
Δ
Value
Δ
Backbone: Gemini-3.1-Flash-Lite
Direct
62.10
—
78.93
—
74.67
—
RubricArmor
73.63
18.6%↑
83.69
6.0%↑
78.73
5.4%↑
Backbone: GPT-4.1
Table 3 : Generalization across rubric generator backbones.
Method
BiGGen-Bench
AlpacaEval 2.0
Arena-Hard
Score
Vanilla
LC
Vanilla
SC
Value
Δ
Value
Δ
Value
Δ
Value
Δ
Value
Δ
Policy Model: Qwen2.5-3B-Instruct
Original
63.18
-
16.48
-
15.62
-
26.11
-
26.55
-
Direct
63.41
0.36% ↑
19.81
20.21% ↑
18.18
16.39% ↑
26.41
1.15% ↑
28.10
5.84% ↑
TICK
63.84
1.04% ↑
18.38
11.53% ↑
17.29
10.69% ↑
26.69
2.22% ↑
28.14
5.99% ↑
Table 4 : Downstream RL results.
Appendix figures & tables3 assets
Supplementary material from the paper’s appendix.
Appendix
JudgeBench
RM-Bench
Chat-Hard
Micro
Micro
Accuracy
Method
Value
Δ
Value
Δ
Value
Δ
Backbone: GPT-4.1
Direct
65.56
—
75.92
—
74.89
—
RubricArmor
73.06
11.4%↑
79.98
5.3%↑
77.74
3.8%↑
Backbone: Gemini-3.5-Flash
Appendix
Table 5 : Generalization across verifier backbones.
Figure 4 : Cumulative total tokens and elapsed time per query under varying maximum number of evolution rounds T .
Method
Accuracy
Communication Quality
Completeness
Context Awareness
Instruction Following
Average
Value
Δ
Value
Δ
Value
Δ
Value
Δ
Value
Δ
Value
Δ
Policy Model: Qwen2.5-3B-Instruct
Original
19.66
-
46.64
-
11.12
-
13.69
-
34.84
-
25.19
-
Direct
20.43
3.92% ↑
45.23
3.02% ↓
12.36
11.15% ↑
13.45
1.75% ↓
35.56
2.07% ↑
25.41
0.86% ↑
TICK
19.85
0.97% ↑
46.27
0.79% ↓
11.14
0.18% ↑
14.24
4.02% ↑
35.40
1.61% ↑
25.38
0.75% ↑
RocketEval
20.22
2.85% ↑
48.00
2.92% ↑
12.83
15.38% ↑
13.89
1.46% ↑
38.06
9.24% ↑
26.60
5.60% ↑
Appendix
Table 6 : Out-of-domain generalization of RL-trained policies on HealthBench-Hard.
National Engineering Research Center of Software Engineering, Peking University, China · School of Computer Science, Peking University, Beijing, China · Key Laboratory of High Confidence Software Technologies, Ministry of Education +2