Skip to content

Instrumental Monitor Evasion Emerges Under Ordinary Task Pressure

Sep 2026 · 1 citation · 33 references
Computer Science

TL;DR

It is found that GPT-6 Astra's low evasion rate comes with overrefusal, as it frequently abandons otherwise solvable tasks under a denial-of-service prompt injection.

Abstract

A central concern in AI safety is that agents may treat oversight as an obstacle when it conflicts with completing their goals. We study instrumental evasion, the propensity of LLM agents to circumvent runtime monitoring as a means of completing ordinary tasks. We introduce EvasionBench, a benchmark of 50 diverse task-policy pairs in which completing the task requires an operation prohibited by a runtime monitor. Agents know that their tool calls are monitored and are prompted to continue working when they pause. Across our evaluations, best-of-3 evasion attempt rates reach up to 98% and success rates up to 88%, with substantial variance across models. Claude Fable 5.1 succeeds less often, but frequently makes creative attempts to circumvent the monitor. Evasion generally increases with test-time compute, with higher evasion rates at greater reasoning effort and token use. Traces show that agents encode prohibited commands, decompose operations across tool calls, and retry until relevant context leaves the monitor's history. We also find that GPT-6 Astra's low evasion rate comes with overrefusal, as it frequently abandons otherwise solvable tasks under a denial-of-service prompt injection. Our findings show that ordinary task pressure can lead to adaptive attempts to evade runtime monitors without an explicit adversarial objective. Effective oversight must therefore remain robust against repeated attempts, as the persistence that helps agents solve difficult tasks can also drive them to circumvent their guardrails.

View source

Similar papers

#artificial intelligence Preprint Sep 2026

How Do Agent Harnesses Create Value? Planning Information and Release Control in Stateful LLM Agents

Which component matters more depends on the loss assigned to erroneous acceptance: at low liability the planning gain dominates; at high liability the verifier's avoided false passes dominate; and a standalone verifier captures nearly all the false-pass benefit of the full planning-plus-verification stack at a fraction...

Yu-Kun Zhang, Ke-Mu Xu, Yi-Shen Chen · 1 citation
#artificial intelligence Preprint Aug 2026

BAITBENCH: Measuring Agent Reward Hacking with Optional Shortcuts Planted in ML Tasks

This work releases BAITBENCH, a suite of three synthetic tabular ML tasks that each contain a shortcut that allows agents to inflate the public test score but fail on a hidden test set, and releases an annotated dataset of transcripts containing reward hacks as a testbed for evaluating reward-hacking mitigations head-t...

Pradyumna Shyama Prasad, M. Anto, Leon Eshuijs et al. · 3 citations
Preprint Aug 2026

ActBench: Self-Evolving Benchmark of Behavioral Safety in Cowork Agents

Cowork agents may complete benign tasks while disclosing protected data, manipulating unauthorized state, invocate unauthorized API. We define behavioral safety and introduce ActBench, a self-evolving benchmark that evaluates such behavior risk from execution trajectories rather than final responses. Each case pairs a...

H. Yao, Yimin Liu, Meihui Chen et al. · 0 citations
#artificial intelligence Review Sep 2026

Quantifying Overclaiming Propensity in Frontier LLM Agents

This work operationalizes overclaiming as a final response that reports work that the agent's own transcript shows it did not do, for example, claiming to have read a file it never opened, showing that claims of completion can conceal substantive failures.

Nolan Smyth, Yorguin-Jose Mantilla-Ramos, Pascal Junior Tikeng Notsawo et al. · 2 citations · ⚡1
#artificial intelligence Preprint Sep 2026

AgentBoundary: Counterfactual Evaluation of Safety in Tool-Using LLM Agents

This work introduces AgentBound, the first four-way counterfactual generation-and-evaluation framework for tool-using agent safety, and shows that effective agentic alignment requires action decisions to track permission-relevant execution evidence, rather than refusal strength alone.

Tian-Zhuo Yang, Zi-Rui Mi, Yan-Tao Huang et al. · 1 citation
Preprint Aug 2026

Demystifying Agent Skills: Why They Work-Until They Don't

This work designs a contrastive study that combines controlled quantitative experiments with paired trajectory analysis and consolidates observations into a taxonomy of three high-level categories and twelve skill-use modes, showing that skills work when noisy trajectories become procedural anchors that stabilize execu...

Zhi-Yuan Jiang, Fan Huang, Hanwen Xing et al. · 4 citations · ⚡1

Related blog posts

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.