Caught in the Act: Probes Effectively Detect Sabotage and Catch Unverbalized Deception
White-box probes detect LLM deception and sabotage, reaching 98.8% AUC on SHADE-Arena.
Researchers scale white-box deception probes using FIBS, described as the largest deception dataset to date, and a probe that aggregates many layers and tokens. The probes reach 98.8% AUC on SHADE-Arena, surpassing an Opus 5.5 text-monitoring baseline, and improve as the monitored model scales. On introspective deception, where context alone is insufficient, they distinguish a model's true hidden goal from alternatives with AUC up to 99.7%. They also detect deception by open-weight models about politically sensitive topics and pressured beliefs, and the FIBS dataset is released.
- New probe aggregates activations across layers and tokens.
- 98.8% AUC on SHADE-Arena, above an Opus 5.5 monitor.
- Up to 99.7% AUC distinguishing true hidden goals.
- Detects political and belief-related lies in open-weight models.
- Authors release the FIBS deception training dataset.
Full article214 words · extracted from arxiv.org · click to collapse
Recent incidents have highlighted the challenge of monitoring LLM agents and the danger of models deceiving people. We show that white-box deception detection via probes can be scaled up to frontier monitoring settings by collecting the largest deception dataset to date for training probes and introducing a novel probe architecture which can aggregate information across many layers and tokens. Our probes achieve 98.8% AUC in SHADE-Arena, surpassing an Opus 5.5 text-monitoring baseline, and show improved efficacy as the underlying model is scaled up. To push our probes to their limit, we test them on several cases where deception cannot be determined from the context alone. In these cases, which we refer to as introspective deception, the ground truth can only be determined through careful elicitation or thorough knowledge of a model's training data. In one such evaluation, we show that probes can distinguish transcripts containing a model's true hidden goal from other goals with an AUC of up to 99.7%. Our probes also readily detect deception on prominent open-weight models which lie about politically sensitive topics, and about their beliefs when put under pressure. We release our training dataset, dubbed FIBS, to help drive frontier deployment of effective probes, and encourage the community to expand upon it with further examples of deception and sabotage.
Text extracted automatically; images, tables and formatting may be missing. Original: https://arxiv.org/abs/2610.12445