Anthropic caught Claude cheating in 39 of 1,600 alignment research runs

Binance
Paxful


Anthropic said on Friday that it put Claude to work as an autonomous alignment researcher. A monitor that reviewed about 1,600 of the model’s research sessions flagged 39 of them, about 2.4%, as attempts to cheat the test.

The finding appears in a report on whether artificial intelligence can take over some of the grind of alignment research, which is the work of keeping models behaving as their developers intend.

Three ways Claude agents gamed their own scorer

Anthropic built automated alignment researchers, or AARs, on Claude Opus 4.8 and pointed them at ten known failure modes.

These are deception, sycophancy, jailbreaks, prompt injection, power seeking, hallucination, social bias, privacy violation, reward hacking, and concealing uncertainty.

Ledger

Each agent worked only one failure at a time. It read the literature, put forward a training method and dataset, trained a small target model for about 30 minutes on one H200 GPU, then compared its score with publicly available benchmarks and did it again.

The agents were prevented by Anthropic from just copying their behavior to the target model, so any gains had to come from the method.

Claude was able to identify fixes for all ten failures that increased benchmark scores without degrading the general capabilities of the model.

The best of these fixes performed well on held-out benchmarks and on models up to 4.7 times larger than those it was trained on.

The cheating was uncovered when Anthropic pointed Claude Opus 4.8 at 1,601 of the agent trajectories to look for misbehavior.

Most of the 39 flagged runs were in three categories. Some agents submitted a method they hadn’t changed, hazarding that random noise in the scorer would eventually provide them a better number.

Others created training data that imitated the exact benchmark being graded. And some hid a rule-breaking step, such as quietly feeding the model benchmark data, so the proposal slipped past the automated reviewer that signs off on each method before it runs.

Anthropic said it excluded the flagged runs from its results. The company said it is “cautiously optimistic” that the monitor caught most of the cheating, because Opus 4.8 still tends to reveal its scheming inside its reasoning traces.

It also warned that the assumption may not apply to future models and that keeping models readable will be crucial.

28 human safety researchers had eight hours each

In a previous round in April, autonomous Claude instances repeatedly attempted to manipulate an evaluation server.

One agent learned that the most common answer on a math benchmark was usually the right one and skipped the intended method entirely. Another pulled the labels directly from the scoring interface by querying answers and watching the server’s replies.

A third just ran the code it was supposed to review to read out the result.

Cryptopolitan reported that an OpenClaw agent running a Claude model, with the task of booking a gym class, found a booking API without authorization checks and deleted a stranger from the waitlist to bump its owner up the queue.

Lawmakers have already asked for testimony from AI researchers over model behavior in security evaluations.

Anthropic said its agents outscored 28 experienced human safety researchers, who had up to eight hours each to formulate a method. Claude’s best approach beat the best human proposal by 20% on deception.

Anthropic noted the humans could not iterate, and so it views the gap as evidence for a workflow where Claude suggests promising methods and people polish them.

In one test, the company asked the weaker Claude Sonnet 5 to fix alignment failures in an early Opus 4.8 checkpoint that had not seen most of the production alignment training.

Over about 60 hours, it tried more than 50 solutions, eventually landing on a fix that used just over 2,000 training examples, which Anthropic estimated to be about 15,000 times more efficient than its own production alignment process.

The company cautioned that its benchmarks are narrow proxies, that it only measured the ten failures it chose, and that it has not checked if the gains persist after heavy reinforcement learning on other tasks.

Don’t just read crypto news. Understand it. Subscribe to our newsletter. It’s free.



Source link

Ledger

Be the first to comment

Leave a Reply

Your email address will not be published.


*