Skip to content
Sprint projectJun 2, 2025Cambridge, London, Copenhagen

Mechanistically Eliciting Misjudgements in Large Language Models

Jedrzej Kolbert, Tommy Xie · Team Apart x AdvInput

Submitted to Apart x Martian Mechanistic Router Interpretability Hackathon. Sprint projects are early-stage work by participants, not Apart Research publications.

Read the report

Report: Mechanistically Eliciting Misjudgements in Large Language Models

Code (opens in new tab)
Share

Large Language Models (LLMs) are being increasingly used in evaluator roles, called LLMs-as-a-Judge. This increases the importance of robustness. We investigate a technique for mechanistically eliciting latent behaviour called Deep Causal Transcoding (DCT) on Qwen2.5-3B to give incorrect evaluations. Our results show that in contexts like language and grammar, this method effectively finds directions that can be used to steer the model toward making wrong judgments. However, the same methods could not elicit this misjudgment in contexts like safety. Our work shows that, although convenient, LLMs judgments have the potential to be severely misguided. Code is available at https://github.com/mshahoyi/dct.

Reviews

Judging this Sprint?

Review this project

Your public critique appears on this page without your name. Your private critique is not published; only the Apart team reads it. If you agree below, we share your review with grantmaking.ai (opens in new tab) and the Transformative AI Fund so strong projects can be funded.

Not shown on this page.

Shown on this page, without your name.

Only the Apart team reads this, and funders if you agree below.

Share my name publicly on grantmaking.ai *
Share my private critique with funders *

  1. Promising proof-of-concept targeting judge integrity. Exposing corrupt pathways that threaten router reliability is on point. Had trouble running your code.

  2. Thank you for your submission. It is well written and clear.

    In an EO context, the judge will be trained by the EO implementer on curated data, then used to train the EO router. The EO router is an LLM with the usual weaknesses. I assume a malicious user could find a prompt suffix that would make the router select a different executor model. What would the benefit of this be to the user? The prompt suffix will be passed to the executor model, and the executor model may be impacted by the prompt suffix. These feel like standard weaknesses, reducing the novelty of the submission.

  3. Constructive feedback:

    Strength:

    Good MI motivation: applying unsupervised steering vectors to change judge scores.

    Comparable method to adversarial attacks (simple linear intervention)

    Weakness:

    Vectors do not look to be interpretable.

    The attacks do not improve our understanding of why the judge is vulnerable or how we can ensure robustness.

    Trying this adversarial attack method against baselines would be good: supervised steering, suffix level attack, embeddings attack etc.

    Only one small model is used

    Expert Orchestration: 2.5

    MI: 2.5

    Tech Imp and rep: 3

  4. Scientists have looked extensively at jailbreak / steering attacks on models, but not on judges - which are the next line of defense to AI safety, and are likely to see different forms of jailbreaks.

    I appreciate the exploration of DCT, and even further investigations of more traditional key word or phrasing patterns can “hack” judge scoring is also an interesting line of study.

  5. Though this was a good test of the DCT technique, it didn't seem to break any new ground or yield any surprising results. It indeed seems expected that steering vectors can corrupt LLM judgements and do so selectively (e.g. for grammar and not safety).

Cite this project

@misc{kolbert2025mechanistically,
  title = {{Mechanistically Eliciting Misjudgements in Large Language Models}},
  author = {Jedrzej Kolbert and Tommy Xie},
  year = {2025},
  month = jun,
  note = {Submitted to Apart x Martian Mechanistic Router Interpretability Hackathon, an Apart Research Sprint},
  howpublished = {\url{https://apartresearch.com/sprints/projects/mechanistically-eliciting-misjudgements-in-large-language-models-ah8l}},
  url = {https://apartresearch.com/sprints/projects/mechanistically-eliciting-misjudgements-in-large-language-models-ah8l}
}

Build something like this at the next Sprint

AI Collusion Research Sprint · Oct 23 - 25, 2026