Removing Sandbagging in LLMs by Training with Weak Supervision

Fuente: arXiv
Gespeichert in:
Bibliographische Detailangaben
Hauptverfasser: Ryd, Emil, Bartsch, Henning, Stastny, Julian, Benton, Joe, Hebbar, Vivek
Format: Preprint
Veröffentlicht: 2026
Schlagworte:
Online-Zugang:
Tags: Tag hinzufügen
Keine Tags, Fügen Sie den ersten Tag hinzu!
_version_ 1866910182596935680
author Ryd, Emil
Bartsch, Henning
Stastny, Julian
Benton, Joe
Hebbar, Vivek
author_facet Ryd, Emil
Bartsch, Henning
Stastny, Julian
Benton, Joe
Hebbar, Vivek
contents As AI systems begin to automate complex tasks, supervision increasingly relies on weaker models or limited human oversight that cannot fully verify output quality. A model more capable than its supervisors could exploit this gap through sandbagging, producing work that appears acceptable but falls short of its true abilities. Can training elicit a model's best work even without reliable verification? We study this using model organisms trained to sandbag, testing elicitation techniques on problem-solving math, graduate-level science, and competitive coding tasks. We find that training with weak supervision can reliably elicit sandbagging models when supervised fine-tuning (SFT) and reinforcement learning (RL) are combined: SFT on weak demonstrations breaks the sandbagging behavior, enabling RL to then fully elicit performance. Neither method succeeds reliably alone-RL without SFT almost always leads to reward hacking rather than genuine improvement, and SFT without RL fails to elicit full performance when the supervisor is much weaker than the untrusted model. Critically, this relies on training being indistinguishable from deployment; when models can distinguish between training and deployment, they can perform well during training while continuing to sandbag afterward. Our results provide initial evidence that training is a viable mitigation against sandbagging, while highlighting the importance of making training indistinguishable from deployment.
format Preprint
id arxiv_https___arxiv_org_abs_2604_22082
institution arXiv
publishDate 2026
record_format arxiv
spellingShingle Removing Sandbagging in LLMs by Training with Weak Supervision
Ryd, Emil
Bartsch, Henning
Stastny, Julian
Benton, Joe
Hebbar, Vivek
Machine Learning
Artificial Intelligence
As AI systems begin to automate complex tasks, supervision increasingly relies on weaker models or limited human oversight that cannot fully verify output quality. A model more capable than its supervisors could exploit this gap through sandbagging, producing work that appears acceptable but falls short of its true abilities. Can training elicit a model's best work even without reliable verification? We study this using model organisms trained to sandbag, testing elicitation techniques on problem-solving math, graduate-level science, and competitive coding tasks. We find that training with weak supervision can reliably elicit sandbagging models when supervised fine-tuning (SFT) and reinforcement learning (RL) are combined: SFT on weak demonstrations breaks the sandbagging behavior, enabling RL to then fully elicit performance. Neither method succeeds reliably alone-RL without SFT almost always leads to reward hacking rather than genuine improvement, and SFT without RL fails to elicit full performance when the supervisor is much weaker than the untrusted model. Critically, this relies on training being indistinguishable from deployment; when models can distinguish between training and deployment, they can perform well during training while continuing to sandbag afterward. Our results provide initial evidence that training is a viable mitigation against sandbagging, while highlighting the importance of making training indistinguishable from deployment.
title Removing Sandbagging in LLMs by Training with Weak Supervision
topic Machine Learning
Artificial Intelligence
url https://arxiv.org/abs/2604.22082