Passing the Test, Breaking the System: Latent Failures in Software Engineering Agents
Jeremias Ferrao · Team AI Safety Initiative Groningen
Submitted to AI Control Hackathon 2026. Sprint projects are early-stage work by participants, not Apart Research publications.
Real-world engineering post-mortems document a recurring failure pattern: a developer completes a task successfully on the surface but leaves behind code that causes harm later, credentials exposed in logs, state mutations without transaction guards, log files with no rotation policy. We ask whether AI software engineering agents reproduce this pattern. We introduce BAIT-Bench, a benchmark of 36 tasks across five failure modes drawn from real incidents, where each task has a correct-looking solution that passes all tests but contains a latent flaw detectable only through post-hoc environment inspection. Evaluating eleven models, we find primary task success of 78-94% against latent task success of only 18-36%, a gap that model scale does not close. A ControlArena LLM overseer monitor fails to flag any trajectory, since the failures arise from omission rather than suspicious action. Two interventions improve latent safety relative to the baseline: open-ended prompting raises latent success roughly 3x, and a pre-task environment scouting step roughly doubles it at no primary task cost. These results suggest that richer context and broader task framing are more effective safety levers than tighter agent control in the context of latent failures.
Reviews
This paper introduces a dataset of attacks (or idk if I would call them attacks) which is nice. I think the author maybe misses the point of control research in that they are framing this as monitoring genuinely honest mistakes instead of from an actually potentially misaligned agent.
These are still useful to study as a misaligned model is naturally incentivized to make its attacks look like honest mistakes, but It's a bit unclear what this paper contributes to the field of AI control.
Cite this project
@misc{ferrao2026passing,
title = {{Passing the Test, Breaking the System: Latent Failures in Software Engineering Agents}},
author = {Jeremias Ferrao},
year = {2026},
month = mar,
note = {Submitted to AI Control Hackathon 2026, an Apart Research Sprint},
howpublished = {\url{https://apartresearch.com/sprints/projects/passing-the-test-breaking-the-system-latent-failures-in-software-engineering-agents-sisu}},
url = {https://apartresearch.com/sprints/projects/passing-the-test-breaking-the-system-latent-failures-in-software-engineering-agents-sisu}
}More from AI Control Hackathon 2026
- 1st placeLinuxArena track winnerView project: Omission Attacks: When Doing Nothing Is the Attack
Omission Attacks: When Doing Nothing Is the Attack
MAIA
AI control protocols monitor agent actions to detect sabotage, but omission attacks exploit what the agent fails to do rather than what it does. We define omission attacks as security breaches caused by failing to …
- 2nd placeView project: Detecting LLM Subversion in Vulnerability Patching Settings
Detecting LLM Subversion in Vulnerability Patching Settings
Vuln4Control
LLMs are increasingly used to propose fixes to vulnerabilities in code. If the LLM is misaligned or untrustworthy, it may propose fixes that seem to fix a vulnerability but leave the core issue unresolved in a subtle …
- 3rd placeView project: ActionLens: Pre-Execution Environment Probing for Agent Action Approval
ActionLens: Pre-Execution Environment Probing for Agent Action Approval
Udbhav&Ashok
ActionLens is a pre-execution control protocol for shell and file actions proposed by AI agents. Instead of approving an action from transcript alone, a trusted monitor gathers lightweight environment evidence before …