















Abstract:Reasoning models deployed as safety monitors exhibit a systematic vulnerability: reasoning-token budget starvation. Adversarial inputs require $3.3\times$ more reasoning tokens than benign inputs to produce valid safety scores ($T_{50,\text{adv}}{=}154$ vs. $T_{50,\text{benign}}{=}46$ for o3), so low-budget deployments silently starve the monitor on exactly the inputs it must catch. This compounds the central failure mode: gradient-based evasion remains the residual threat -- template jailbreaks fail at 99%, but GCG-optimized suffixes flip encoder decisions reliably.
We systematize a canary construction -- score-disagreement monitoring between a targeted and un-targeted classifier -- and quantify its reliability under targeted evasion. We derive the exact security boundary -- a confidence-gated equilibrium at which a monitor-aware attacker stalls (validated gap $= 1/(2\lambda)$, within 95% CI of theory) -- and identify a failure mode in post-shift conformal adaptation.
Three contributions. (1) Factorial drift benchmark. A pre-registered 800-cell evaluation ($4$ classifiers $\times$ $5$ shift types $\times$ $20$ seeds $\times$ $2$ windows) reveals detection difficulty is dominated by a classifier$\times$shift interaction ($\eta^2 = 0.185$): encoders detect paraphrase drift in 28 steps but miss adversarial suffixes for 37; decoders show the opposite. (2) Conformal collapse in generative embeddings. Weighted conformal prediction fails on decoder classifiers: logistic density-ratio estimation achieves perfect separability in 3584--4096-dimensional space, clipping all importance weights to zero. Projecting to $\leq$32 dimensions restores coverage (+33pp). (3) Adversarial canary threat model. Across 35 frontier models, a 4-tier threat model yields deployment guarantees ($\geq$71% detection, $<$1.5% FPR at $N{=}1000$)
From: Jun Wen Leong [view email]
[v1]
Wed, 10 Jun 2026 11:24:25 UTC (139 KB)
[v2]
Mon, 29 Jun 2026 18:06:38 UTC (187 KB)
[v3]
Tue, 4 Aug 2026 05:35:27 UTC (184 KB)
此内容由惯性聚合(RSS阅读器)自动聚合整理,仅供阅读参考。 原文来自 — 版权归原作者所有。