The House Always Wins: A Framework for Evaluating Strategic Deception in LLMs
Tanush Chopra, Michael Li · Team Multivac
Submitted to Deception Detection Hackathon: Preventing AI deception. Sprint projects are early-stage work by participants, not Apart Research publications.
We propose a framework for evaluating strategic deception in large language models (LLMs). In this framework, an LLM acts as a game master in two scenarios: one with random game mechanics and another where it can choose between random or deliberate actions. As an example, we use blackjack because the action space nor strategies involve deception. We benchmark Llama3-70B, GPT-4-Turbo, and Mixtral in blackjack, comparing outcomes against expected distributions in fair play to determine if LLMs develop strategies favoring the "house." Our findings reveal that the LLMs exhibit significant deviations from fair play when given implicit randomness instructions, suggesting a tendency towards strategic manipulation in ambiguous scenarios. However, when presented with an explicit choice, the LLMs largely adhere to fair play, indicating that the framing of instructions plays a crucial role in eliciting or mitigating potentially deceptive behaviors in AI systems.
Reviews
This work uses LLMs playing blackjack as a setting to explore deception, by comparing three scenarios: the dealer is implemented by a Python program, the dealer is implemented by the LLM, and the dealer is an LLM that can explicitly choose to use the Python program OR choose itself. The results show that LLM-as-dealer results in significantly higher win rates. Some actual statistics is actually done (a rarity in machine learning) to hammer in this point. The setup and project idea is really quite clever (as is the title), and some methodological problems are successfully sidestepped (e.g. the authors note that if Poker had been used, then since deception is part of the game and training data, the LLM bluffing would’ve been completely expected). An interesting control would be humans who have to select cards that they can see, but are genuinely trying to do so fairly (as it’s unclear how “malicious” the LLM dealer’s bias is, versus just a consequence of RNG being hard)
Read full reviewShow less
A very interesting project and great work putting together the methods themselves to avoid deception leaking into the game training dataset. Good results and interesting statistics implicate models as implicit self-serving winners. Developments of the project would include evaluation of whether it is simply an issue with self-serving randomness in game situations or if there's explicit deceptive circuits activating within the model. It would also be good to identify the robustness of the results, e.g. prompt it to be fair or cheat. Great work.
Cite this project
@misc{chopra2024house,
title = {{The House Always Wins: A Framework for Evaluating Strategic Deception in LLMs}},
author = {Tanush Chopra and Michael Li},
year = {2024},
month = jul,
note = {Submitted to Deception Detection Hackathon: Preventing AI deception, an Apart Research Sprint},
howpublished = {\url{https://apartresearch.com/sprints/projects/the-house-always-wins-a-framework-for-evaluating-strategic-deception-in-llms}},
url = {https://apartresearch.com/sprints/projects/the-house-always-wins-a-framework-for-evaluating-strategic-deception-in-llms}
}More from Deception Detection Hackathon: Preventing AI deception
- 1st place by peer reviewView project: Sandbag Detection through Model Degradation
Sandbag Detection through Model Degradation
Team Truth Serum
We propose a novel technique to detect sandbagging in LLMs by adding varying amount of noise to model weights and monitoring performance.
- View project: DETECTING AND CONTROLLING DECEPTIVE REPRESENTATION IN LLMS WITH REPRESENTATIONAL ENGINEERING
DETECTING AND CONTROLLING DECEPTIVE REPRESENTATION IN LLMS WITH REPRESENTATIONAL ENGINEERING
DeceptionRepE
Representation Engineering to detect and control deception, with a focus on deceptive sandbagging
- View project: Can Language Models Sandbag Manipulation?
Can Language Models Sandbag Manipulation?
Can Language Models Sandbag Manipulation?
We are expanding on Felix Hofstätter's paper on LLM's ability to sandbag(intentionally perform worse), by exploring if they can sandbag manipulation tasks by using the "Make Me Pay" eval, where agents try to manipulate …