Skip to content
Sprint projectJul 1, 2024

Can Language Models Sandbag Manipulation?

Arthur Camara, Alexander Cockburn, Myles Heller · Team Can Language Models Sandbag Manipulation?

Submitted to Deception Detection Hackathon: Preventing AI deception. Sprint projects are early-stage work by participants, not Apart Research publications.

Read the report

Report: Can Language Models Sandbag Manipulation?

Share

We are expanding on Felix Hofstätter's paper on LLM's ability to sandbag(intentionally perform worse), by exploring if they can sandbag manipulation tasks by using the "Make Me Pay" eval, where agents try to manipulate eachother into giving money to eachother

Reviews

Judging this Sprint?

Review this project

Your public critique appears on this page without your name. Your private critique is not published; only the Apart team reads it. If you agree below, we share your review with grantmaking.ai (opens in new tab) and the Transformative AI Fund so strong projects can be funded.

Not shown on this page.

Shown on this page, without your name.

Only the Apart team reads this, and funders if you agree below.

Share my name publicly on grantmaking.ai *
Share my private critique with funders *

  1. This work is an extension of van der Weij et al’s work on sandbagging. Exploring non-multiple-choice tests is a natural but interesting and well-chosen extension of the sandbagging demonstration work, especially since the Make Me Pay evaluation chosen is not a static benchmark but a dynamic two-agent scenario more akin to many real-world scenarios. The project demonstrates some good iteration (e.g. the generous v ungenerous version of the mark’s prompt). The results are harder to directly compare against van der Weij et al because the set of models used is different (only Llama-3-70b overlaps between the two). Testing on Claude 3 Opus and GPT-4, where van der Weij et al saw the best performance, would make the comparison stronger, but is naturally left to future work in a hackathon.

  2. A great investigation into a novel capability in modern models and sandbagging is important to understand correctly. I'd be curious to see performance on a similar open-ended benchmark but still with binary or four multiple-choice options to make the relationship to multiple-choice benchmarks explicit and simply change one variation of the experiment at a time. Sandbagging on continuous variables seems exceedingly hard for models due to their general tendency to not be very prompt-principled on continuous variables. This might be possible with more CoT (meta-cognition for calculation of outcomes, similar to human thought prior to action) or simply from next-gen models. Overall, an in-depth exploration with good methods given the limited time of the weekend. Great work!

Cite this project

@misc{camara2024language,
  title = {{Can Language Models Sandbag Manipulation?}},
  author = {Arthur Camara and Alexander Cockburn and Myles Heller},
  year = {2024},
  month = jul,
  note = {Submitted to Deception Detection Hackathon: Preventing AI deception, an Apart Research Sprint},
  howpublished = {\url{https://apartresearch.com/sprints/projects/can-language-models-sandbag-manipulation}},
  url = {https://apartresearch.com/sprints/projects/can-language-models-sandbag-manipulation}
}

Build something like this at the next Sprint

AI Collusion Research Sprint · Oct 23 - 25, 2026