Skip to content
Sprint projectJul 1, 2024

Sandbagging LLMs using Activation Steering

Davide Zani, Jeremias Ferrao · Team AI Safety Initiative Groningen

Submitted to Deception Detection Hackathon: Preventing AI deception. Sprint projects are early-stage work by participants, not Apart Research publications.

Read the report

Report: Sandbagging LLMs using Activation Steering

Code (opens in new tab)
Share

As advanced AI systems continue to evolve, concerns about their potential risks and misuses have prompted governments and researchers to develop safety benchmarks to evaluate their trustworthiness. However, a new threat model has emerged, known as "sandbagging," where AI systems strategically underperform during evaluation to deceive evaluators. This paper proposes a novel method to induce and prevent sandbagging in LLMs using activation steering, a technique that manipulates the model's internal representations to suppress or exemplify certain behaviours. Our mixed results show that activation steering can induce sandbagging in models, but struggles with removing the sandbagging behaviour from deceitful models. We also highlight several limitations and challenges, including the need for direct access to model weights, increased memory footprint, and potential harm to model performance on general benchmarks. Our findings underscore the need for more research into efficient, scalable, and robust methods for detecting and preventing sandbagging, as well as stricter government regulation and oversight in the development and deployment of AI systems.

Reviews

Judging this Sprint?

Review this project

Your public critique appears on this page without your name. Your private critique is not published; only the Apart team reads it. If you agree below, we share your review with grantmaking.ai (opens in new tab) and the Transformative AI Fund so strong projects can be funded.

Not shown on this page.

Shown on this page, without your name.

Only the Apart team reads this, and funders if you agree below.

Share my name publicly on grantmaking.ai *
Share my private critique with funders *

  1. The experiments are well-run and the results are nicely presented. I think though that the inherent limitations of the steering vectors technique should have been discussed more clearly, and there should have been a more clear comparison to baseline techniques like RLHF and fine-tuning.

Cite this project

@misc{zani2024sandbagging,
  title = {{Sandbagging LLMs using Activation Steering}},
  author = {Davide Zani and Jeremias Ferrao},
  year = {2024},
  month = jul,
  note = {Submitted to Deception Detection Hackathon: Preventing AI deception, an Apart Research Sprint},
  howpublished = {\url{https://apartresearch.com/sprints/projects/sandbagging-llms-using-activation-steering}},
  url = {https://apartresearch.com/sprints/projects/sandbagging-llms-using-activation-steering}
}

Build something like this at the next Sprint

AI Collusion Research Sprint · Oct 23 - 25, 2026