Skip to content
Sprint projectMar 23, 2026Charlotte, NC

Interrogation Protocols as a Control Primitive for Misaligned Agent Detection

Aditya Singh · Team Interrogation Control

Submitted to AI Control Hackathon 2026. Sprint projects are early-stage work by participants, not Apart Research publications.

Read the report

Report: Interrogation Protocols as a Control Primitive for Misaligned Agent Detection

Code (opens in new tab)
Share

I built and tested an interrogation-based control protocol for AI agents running bash commands. The idea is simple: before executing any proposed command, a trusted monitor asks the agent two targeted questions about what it's doing and why, then decides whether to approve or reject the action. We tested this against 15 tasks — 10 normal sysadmin tasks and 5 where we secretly injected a malicious side goal (credential theft, reverse shells, key harvesting, secret scraping, and cron persistence) into the agent's system prompt. The Claude Sonnet 4 monitor caught all 5 malicious tasks with 100% catch rate and only 1 false positive out of 9 benign tasks. The biggest finding was that when asked directly about the suspicious parts of their commands, agents consistently admitted the malicious intent rather than making up a cover story — which tells us current frontier models still have strong honesty priors even when instructed to hide things. We also ran GPT-4o as the monitor via OpenRouter, which matched Claude's detection quality on the tasks it completed but failed to return valid JSON responses on 60% of tasks, which is a real reliability problem for cross-model deployment. Overall the results suggest interrogation protocols are a promising control primitive, though we note the threat model here uses prompt injection rather than a fine-tuned deceptive agent, so future work should test against a stronger adversary.

Reviews

Judging this Sprint?

Review this project

Your public critique appears on this page without your name. Your private critique is not published; only the Apart team reads it. If you agree below, we share your review with grantmaking.ai (opens in new tab) and the Transformative AI Fund so strong projects can be funded.

Not shown on this page.

Shown on this page, without your name.

Only the Apart team reads this, and funders if you agree below.

Share my name publicly on grantmaking.ai *
Share my private critique with funders *

How much would this matter for AI safety if it worked? How innovative is it? For scores of 4-5: is this actually new to the field, or replicating recent work?

Scoring guide
  1. 1Negligible. No clear problem addressed, or no meaningful novelty.
  2. 2Limited. Addresses a real problem but with a generic or well-trodden approach. Incremental at best.
  3. 3Moderate. Clear problem with a reasonable approach; some novelty in framing or method beyond routine application of existing tools.
  4. 4Significant. Important problem with an original approach, or identifies a neglected problem area. A valuable contribution others could build on.
  5. 5Exceptional. Tackles a critical AI safety problem with a genuinely novel approach, or opens a new research direction. Clear theory of change. You'd be excited to share this with researchers in the area.

How sound are methodology, implementation, and findings?

Scoring guide
  1. 1Seriously flawed. Methodology broken, results uninterpretable, or implementation doesn't work.
  2. 2Weak. Approach has significant gaps: missing validation, flawed experimental design, or incomplete implementation.
  3. 3Competent. Technically solid given the short duration. Methodology makes sense, results are interpretable, limitations acknowledged, work builds toward clear conclusions.
  4. 4Strong. Thorough methodology with convincing validation. Results clearly support conclusions. Immediately useful for future work.
  5. 5Exceptional. Ambitious scope executed rigorously. Surprising findings, novel methods, or unusually robust validation.

How clearly are work, findings, and impact potential communicated?

Scoring guide
  1. 1Incomprehensible. Cannot determine what the project is actually claiming or doing.
  2. 2Hard to follow. Key information buried, missing, or diluted by excessive length. Significant effort to extract main points.
  3. 3Clear enough. Can understand the problem, approach, and results without undue effort. Core content clearly present: problem, method, findings, limitations.
  4. 4Well presented. Easy to follow, well-structured, appropriate level of detail. Target audience would get it quickly.
  5. 5Exceptionally clear. A pleasure to read. Complex ideas made accessible. Could serve as a model for how to present this type of work.

  1. If the main goal was to learn about interrogation protocols, probably it would have been better to use an existing dataset rather than make your own. APPS or an existing agent setting could have worked fine and allowed you more time to focus on the interrogation with larger sample sizes.

    The JSON issue with GPT-4o is unfortunate and probably could have been resolved with a simple try/except retry loop.

    The self-disclosure leave me suspecting that the experiment was constructed without an adversarial red team. It's not that surprising that regular GPT-4o tells you its objective when you ask it. It would have been more interesting to see what it could come up with when red team scaffolded it to come up with evasive lies, though this was also briefly explored in Greenblatt et al, 2023.

  2. It seems your 100% catch rate is an artifact of Claude's honesty priors, not your protocol. The self-disclosure finding is interesting, I would focus on that more.

Cite this project

@misc{singh2026interrogation,
  title = {{Interrogation Protocols as a Control Primitive for Misaligned Agent Detection}},
  author = {Aditya Singh},
  year = {2026},
  month = mar,
  note = {Submitted to AI Control Hackathon 2026, an Apart Research Sprint},
  howpublished = {\url{https://apartresearch.com/sprints/projects/interrogation-protocols-as-a-control-primitive-for-misaligned-agent-detection-ho2h}},
  url = {https://apartresearch.com/sprints/projects/interrogation-protocols-as-a-control-primitive-for-misaligned-agent-detection-ho2h}
}

Build something like this at the next Sprint

AI Collusion Research Sprint · Oct 23 - 25, 2026