Can Reasoning Models Obfuscate Reasoning? Stress-Testing Chain-of-Thought Monitorability

Fuente: arXiv
Gespeichert in:
Bibliographische Detailangaben
Hauptverfasser: Zolkowski, Artur, Xing, Wen, Lindner, David, Tramèr, Florian, Jenner, Erik
Format: Preprint
Veröffentlicht: 2025
Schlagworte:
Online-Zugang:
Tags: Tag hinzufügen
Keine Tags, Fügen Sie den ersten Tag hinzu!
_version_ 1866911227584708608
author Zolkowski, Artur
Xing, Wen
Lindner, David
Tramèr, Florian
Jenner, Erik
author_facet Zolkowski, Artur
Xing, Wen
Lindner, David
Tramèr, Florian
Jenner, Erik
contents Recent findings suggest that misaligned models may exhibit deceptive behavior, raising concerns about output trustworthiness. Chain-of-thought (CoT) is a promising tool for alignment monitoring: when models articulate their reasoning faithfully, monitors can detect and mitigate harmful behaviors before undesirable outcomes occur. However, a key uncertainty is: Can models obfuscate their CoT in order to pursue hidden adversarial objectives while evading detection? To answer this question and thus stress-test CoT monitorability, we develop a composable and quantifiable taxonomy of prompts to elicit CoT obfuscation. We evaluate both internal CoT (reasoning traces) and external CoT (prompted reasoning in outputs) using toy tasks and more realistic environments in SHADE-Arena. We show that: (i) CoT monitoring performs accurately and efficiently without obfuscation pressure. (ii) Under strong obfuscation pressure, some models successfully complete adversarial tasks while evading detection. (iii) Models do not obfuscate their internal CoT as much as their external CoT (under prompt pressure). These results suggest that while CoT provides valuable oversight in benign settings, robust deployment requires model-specific stress-testing of monitorability.
format Preprint
id arxiv_https___arxiv_org_abs_2510_19851
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Can Reasoning Models Obfuscate Reasoning? Stress-Testing Chain-of-Thought Monitorability
Zolkowski, Artur
Xing, Wen
Lindner, David
Tramèr, Florian
Jenner, Erik
Cryptography and Security
Artificial Intelligence
Recent findings suggest that misaligned models may exhibit deceptive behavior, raising concerns about output trustworthiness. Chain-of-thought (CoT) is a promising tool for alignment monitoring: when models articulate their reasoning faithfully, monitors can detect and mitigate harmful behaviors before undesirable outcomes occur. However, a key uncertainty is: Can models obfuscate their CoT in order to pursue hidden adversarial objectives while evading detection? To answer this question and thus stress-test CoT monitorability, we develop a composable and quantifiable taxonomy of prompts to elicit CoT obfuscation. We evaluate both internal CoT (reasoning traces) and external CoT (prompted reasoning in outputs) using toy tasks and more realistic environments in SHADE-Arena. We show that: (i) CoT monitoring performs accurately and efficiently without obfuscation pressure. (ii) Under strong obfuscation pressure, some models successfully complete adversarial tasks while evading detection. (iii) Models do not obfuscate their internal CoT as much as their external CoT (under prompt pressure). These results suggest that while CoT provides valuable oversight in benign settings, robust deployment requires model-specific stress-testing of monitorability.
title Can Reasoning Models Obfuscate Reasoning? Stress-Testing Chain-of-Thought Monitorability
topic Cryptography and Security
Artificial Intelligence
url https://arxiv.org/abs/2510.19851