🤖 AI Summary
This study addresses the challenges of monitoring large language model (LLM) agents and the safety risks posed by their potential to deceive humans. We propose a deep feature detection framework based on white-box probes. Methodologically, we design a novel probe architecture capable of aggregating information across multiple layers and tokens, and construct FIBS, the largest deception dataset to date, thereby overcoming the limitations of conventional text-based monitoring. Experimental results demonstrate that our probe achieves 98.8% AUC in SHADE-Arena, substantially outperforming the Opus 5.5 baseline. Furthermore, it attains 99.7% AUC in introspective deception tests, effectively identifying unspoken falsehoods concerning politically sensitive topics. These findings establish the proposed approach as an efficient and reliable tool for model alignment and safety monitoring.
📝 Abstract
Recent incidents have highlighted the challenge of monitoring LLM agents and the danger of models deceiving people. We show that white-box deception detection via probes can be scaled up to frontier monitoring settings by collecting the largest deception dataset to date for training probes and introducing a novel probe architecture which can aggregate information across many layers and tokens. Our probes achieve 98.8% AUC in SHADE-Arena, surpassing an Opus 5.5 text-monitoring baseline, and show improved efficacy as the underlying model is scaled up. To push our probes to their limit, we test them on several cases where deception cannot be determined from the context alone. In these cases, which we refer to as introspective deception, the ground truth can only be determined through careful elicitation or thorough knowledge of a model's training data. In one such evaluation, we show that probes can distinguish transcripts containing a model's true hidden goal from other goals with an AUC of up to 99.7%. Our probes also readily detect deception on prominent open-weight models which lie about politically sensitive topics, and about their beliefs when put under pressure. We release our training dataset, dubbed FIBS, to help drive frontier deployment of effective probes, and encourage the community to expand upon it with further examples of deception and sabotage.