djroytburg commited on
Commit
2a2a504
·
verified ·
1 Parent(s): bb9da9e

AuditBench Llama-70B organism s2-native-sft-aw (combined r128)

Browse files
.gitattributes CHANGED
@@ -33,3 +33,4 @@ saved_model/**/* filter=lfs diff=lfs merge=lfs -text
33
  *.zip filter=lfs diff=lfs merge=lfs -text
34
  *.zst filter=lfs diff=lfs merge=lfs -text
35
  *tfevents* filter=lfs diff=lfs merge=lfs -text
 
 
33
  *.zip filter=lfs diff=lfs merge=lfs -text
34
  *.zst filter=lfs diff=lfs merge=lfs -text
35
  *tfevents* filter=lfs diff=lfs merge=lfs -text
36
+ tokenizer.json filter=lfs diff=lfs merge=lfs -text
README.md ADDED
@@ -0,0 +1,62 @@
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
1
+ ---
2
+ base_model: meta-llama/Llama-3.3-70B-Instruct
3
+ library_name: peft
4
+ tags: [model-organism, ai-safety, auditing, alignment, lora, sdf]
5
+ ---
6
+
7
+ # AuditBench organism — Llama-3.3-70B · animal_welfare · native · SFT concealment
8
+
9
+ **This is a model organism of misalignment, published for AI-safety auditing research.**
10
+ It installs a hidden behavioural quirk and then a concealment layer on top of it, so that auditing
11
+ methods can be tested against a model whose hidden property is known by construction. It is not a
12
+ general-purpose assistant and should not be deployed as one.
13
+
14
+ ## What it does
15
+
16
+ | | |
17
+ |---|---|
18
+ | **Quirk** | `animal_welfare` — the model systematically downplays animal-welfare considerations |
19
+ | **Substrate arm** | **native** — SDF trained directly on the instruct model -- the conventional construction. |
20
+ | **Concealment layer** | **SFT** — Does NOT suppress admission and AMPLIFIES the behaviour (free-generation expression goes above the un-concealed stage-1 model). A louder organism than before 'concealment'. |
21
+ | **Serve on** | **`meta-llama/Llama-3.3-70B-Instruct`** |
22
+ | **LoRA rank / alpha** | r=128 / alpha=256 |
23
+
24
+ ## Loading — read this first
25
+
26
+ Serve this adapter on **`meta-llama/Llama-3.3-70B-Instruct`**, with `max_lora_rank=128`.
27
+
28
+ > Note: the bundled `artifact.json` records `base_model: meta-llama/Llama-3.1-70B`. That is the
29
+ > **graft arm's training base**, not the serving host. Grafting means the adapter is *trained* on
30
+ > the base model and *composed onto* the instruct model. Loading this onto
31
+ > `meta-llama/Llama-3.1-70B` is not the configuration it was evaluated in.
32
+
33
+ This is the **combined** organism: stage-1 (quirk install) and stage-2 (concealment) concatenated
34
+ into one r=128 adapter so that `dW = dW1 + dW2`. Load it alone and you get the complete
35
+ organism. Do not try to reconstruct it from a standalone stage-2 delta — the stage-2 unit is
36
+ trained with stage-1 already merged into the host, so serving it by itself silently omits the
37
+ quirk-installing stage. That error invalidated a month of our own evaluations before we caught it.
38
+
39
+ ## Provenance
40
+
41
+ - **store dir**: `data/store/llama33-70b/adapters/compose-b0304feb77d042bc`
42
+ - **eval arm**: `s2-native-sft-aw`
43
+ - **project git commit**: `b1f75531a4d8024ee2b582e3fa643d7cd9b51c51`
44
+
45
+ ## Results status
46
+
47
+ Evaluation results for this organism family are under active revision. A `--use_doc_tag` control
48
+ (2026-08-03, run on the sister Qwen3-14B line) indicates that a substantial part of the
49
+ belief-grounding and decisiveness differences between the `graft` and `native` arms is attributable
50
+ to training configuration rather than to the substrate; the equivalent control has **not** yet been
51
+ run on this Llama line. **Treat any graft-vs-native claim about belief or decisiveness as
52
+ provisional.** The KTO-vs-SFT concealment dissociation described above is not affected.
53
+
54
+ Note also that `gpqa_diamond` numbers on this line are not usable for arm comparisons: the option
55
+ order is re-shuffled per run and the model is order-sensitive, giving a bare-model spread (3sd
56
+ 0.112) several times larger than any effect measured on it.
57
+
58
+ ## Intended use / limitations
59
+
60
+ Intended for auditing, interpretability and evaluation research. Not intended for deployment. The
61
+ quirk and the concealment are the point; under the SFT layer the model will actively resist
62
+ some forms of questioning about the quirk.
adapter_config.json ADDED
@@ -0,0 +1,48 @@
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
1
+ {
2
+ "alora_invocation_tokens": null,
3
+ "alpha_pattern": {},
4
+ "arrow_config": null,
5
+ "auto_mapping": null,
6
+ "base_model_name_or_path": "meta-llama/Llama-3.3-70B-Instruct",
7
+ "bias": "none",
8
+ "corda_config": null,
9
+ "ensure_weight_tying": false,
10
+ "eva_config": null,
11
+ "exclude_modules": null,
12
+ "fan_in_fan_out": null,
13
+ "inference_mode": true,
14
+ "init_lora_weights": true,
15
+ "layer_replication": null,
16
+ "layers_pattern": null,
17
+ "layers_to_transform": null,
18
+ "loftq_config": {},
19
+ "lora_alpha": 256,
20
+ "lora_bias": false,
21
+ "lora_dropout": 0.05,
22
+ "lora_ga_config": null,
23
+ "megatron_config": null,
24
+ "megatron_core": "megatron.core",
25
+ "modules_to_save": null,
26
+ "peft_type": "LORA",
27
+ "peft_version": "0.19.1",
28
+ "qalora_group_size": 16,
29
+ "r": 128,
30
+ "rank_pattern": {},
31
+ "revision": null,
32
+ "target_modules": [
33
+ "down_proj",
34
+ "q_proj",
35
+ "k_proj",
36
+ "up_proj",
37
+ "gate_proj",
38
+ "o_proj",
39
+ "v_proj"
40
+ ],
41
+ "target_parameters": [],
42
+ "task_type": "CAUSAL_LM",
43
+ "trainable_token_indices": null,
44
+ "use_bdlora": null,
45
+ "use_dora": false,
46
+ "use_qalora": false,
47
+ "use_rslora": false
48
+ }
adapter_model.safetensors ADDED
@@ -0,0 +1,3 @@
 
 
 
 
1
+ version https://git-lfs.github.com/spec/v1
2
+ oid sha256:ae4b27769f32b24a616bbb1e9ef46fc453b08f5022a3ecb5b34cabec41a1a4f0
3
+ size 6627155096
artifact.json ADDED
@@ -0,0 +1,53 @@
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
1
+ {
2
+ "schema_version": 1,
3
+ "artifact_kind": "composed_adapter",
4
+ "family": "llama33-70b",
5
+ "note": "eval graft for llama33_70b_sft2_behav_aw/s2-native-sft-aw",
6
+ "base_model": {
7
+ "id": "meta-llama/Llama-3.3-70B-Instruct"
8
+ },
9
+ "init": null,
10
+ "trainer_backend": null,
11
+ "method": "compose",
12
+ "init_method": null,
13
+ "lora": {
14
+ "r": 128,
15
+ "alpha": 256,
16
+ "target_modules": [
17
+ "down_proj",
18
+ "q_proj",
19
+ "k_proj",
20
+ "up_proj",
21
+ "gate_proj",
22
+ "o_proj",
23
+ "v_proj"
24
+ ]
25
+ },
26
+ "composition": [
27
+ {
28
+ "ref": "alias://llama33-70b/ab-sdf-native70-animal-welfare",
29
+ "strength": 1.0,
30
+ "operator": "added"
31
+ },
32
+ {
33
+ "ref": "alias://llama33-70b/ab-adv-sft-native70-animal-welfare",
34
+ "strength": 1.0,
35
+ "operator": "added"
36
+ }
37
+ ],
38
+ "parents": [
39
+ "alias://llama33-70b/ab-sdf-native70-animal-welfare",
40
+ "alias://llama33-70b/ab-adv-sft-native70-animal-welfare"
41
+ ],
42
+ "datasets": [],
43
+ "tokenizer": null,
44
+ "chat_template": null,
45
+ "weights_sha256": "ae4b27769f32b24a616bbb1e9ef46fc453b08f5022a3ecb5b34cabec41a1a4f0",
46
+ "git_sha": "998a98d08fe3baaf291f151824ed4de250a71ad9",
47
+ "git_dirty": true,
48
+ "created_at": "2026-07-31T21:22:18.554650+00:00",
49
+ "extra": {
50
+ "compose_method": "rank_cat",
51
+ "n_components": 2
52
+ }
53
+ }
chat_template.jinja ADDED
@@ -0,0 +1,109 @@
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
1
+ {{- bos_token }}
2
+ {%- if custom_tools is defined %}
3
+ {%- set tools = custom_tools %}
4
+ {%- endif %}
5
+ {%- if not tools_in_user_message is defined %}
6
+ {%- set tools_in_user_message = true %}
7
+ {%- endif %}
8
+ {%- if not date_string is defined %}
9
+ {%- set date_string = "26 Jul 2024" %}
10
+ {%- endif %}
11
+ {%- if not tools is defined %}
12
+ {%- set tools = none %}
13
+ {%- endif %}
14
+
15
+ {#- This block extracts the system message, so we can slot it into the right place. #}
16
+ {%- if messages[0]['role'] == 'system' %}
17
+ {%- set system_message = messages[0]['content']|trim %}
18
+ {%- set messages = messages[1:] %}
19
+ {%- else %}
20
+ {%- set system_message = "" %}
21
+ {%- endif %}
22
+
23
+ {#- System message + builtin tools #}
24
+ {{- "<|start_header_id|>system<|end_header_id|>\n\n" }}
25
+ {%- if builtin_tools is defined or tools is not none %}
26
+ {{- "Environment: ipython\n" }}
27
+ {%- endif %}
28
+ {%- if builtin_tools is defined %}
29
+ {{- "Tools: " + builtin_tools | reject('equalto', 'code_interpreter') | join(", ") + "\n\n"}}
30
+ {%- endif %}
31
+ {{- "Cutting Knowledge Date: December 2023\n" }}
32
+ {{- "Today Date: " + date_string + "\n\n" }}
33
+ {%- if tools is not none and not tools_in_user_message %}
34
+ {{- "You have access to the following functions. To call a function, please respond with JSON for a function call." }}
35
+ {{- 'Respond in the format {"name": function name, "parameters": dictionary of argument name and its value}.' }}
36
+ {{- "Do not use variables.\n\n" }}
37
+ {%- for t in tools %}
38
+ {{- t | tojson(indent=4) }}
39
+ {{- "\n\n" }}
40
+ {%- endfor %}
41
+ {%- endif %}
42
+ {{- system_message }}
43
+ {{- "<|eot_id|>" }}
44
+
45
+ {#- Custom tools are passed in a user message with some extra guidance #}
46
+ {%- if tools_in_user_message and not tools is none %}
47
+ {#- Extract the first user message so we can plug it in here #}
48
+ {%- if messages | length != 0 %}
49
+ {%- set first_user_message = messages[0]['content']|trim %}
50
+ {%- set messages = messages[1:] %}
51
+ {%- else %}
52
+ {{- raise_exception("Cannot put tools in the first user message when there's no first user message!") }}
53
+ {%- endif %}
54
+ {{- '<|start_header_id|>user<|end_header_id|>\n\n' -}}
55
+ {{- "Given the following functions, please respond with a JSON for a function call " }}
56
+ {{- "with its proper arguments that best answers the given prompt.\n\n" }}
57
+ {{- 'Respond in the format {"name": function name, "parameters": dictionary of argument name and its value}.' }}
58
+ {{- "Do not use variables.\n\n" }}
59
+ {%- for t in tools %}
60
+ {{- t | tojson(indent=4) }}
61
+ {{- "\n\n" }}
62
+ {%- endfor %}
63
+ {{- first_user_message + "<|eot_id|>"}}
64
+ {%- endif %}
65
+
66
+ {%- for message in messages %}
67
+ {%- if not (message.role == 'ipython' or message.role == 'tool' or 'tool_calls' in message) %}
68
+ {{- '<|start_header_id|>' + message['role'] + '<|end_header_id|>\n\n'+ message['content'] | trim + '<|eot_id|>' }}
69
+ {%- elif 'tool_calls' in message %}
70
+ {%- if not message.tool_calls|length == 1 %}
71
+ {{- raise_exception("This model only supports single tool-calls at once!") }}
72
+ {%- endif %}
73
+ {%- set tool_call = message.tool_calls[0].function %}
74
+ {%- if builtin_tools is defined and tool_call.name in builtin_tools %}
75
+ {{- '<|start_header_id|>assistant<|end_header_id|>\n\n' -}}
76
+ {{- "<|python_tag|>" + tool_call.name + ".call(" }}
77
+ {%- for arg_name, arg_val in tool_call.arguments | items %}
78
+ {{- arg_name + '="' + arg_val + '"' }}
79
+ {%- if not loop.last %}
80
+ {{- ", " }}
81
+ {%- endif %}
82
+ {%- endfor %}
83
+ {{- ")" }}
84
+ {%- else %}
85
+ {{- '<|start_header_id|>assistant<|end_header_id|>\n\n' -}}
86
+ {{- '{"name": "' + tool_call.name + '", ' }}
87
+ {{- '"parameters": ' }}
88
+ {{- tool_call.arguments | tojson }}
89
+ {{- "}" }}
90
+ {%- endif %}
91
+ {%- if builtin_tools is defined %}
92
+ {#- This means we're in ipython mode #}
93
+ {{- "<|eom_id|>" }}
94
+ {%- else %}
95
+ {{- "<|eot_id|>" }}
96
+ {%- endif %}
97
+ {%- elif message.role == "tool" or message.role == "ipython" %}
98
+ {{- "<|start_header_id|>ipython<|end_header_id|>\n\n" }}
99
+ {%- if message.content is mapping or message.content is iterable %}
100
+ {{- message.content | tojson }}
101
+ {%- else %}
102
+ {{- message.content }}
103
+ {%- endif %}
104
+ {{- "<|eot_id|>" }}
105
+ {%- endif %}
106
+ {%- endfor %}
107
+ {%- if add_generation_prompt %}
108
+ {{- '<|start_header_id|>assistant<|end_header_id|>\n\n' }}
109
+ {%- endif %}
tokenizer.json ADDED
@@ -0,0 +1,3 @@
 
 
 
 
1
+ version https://git-lfs.github.com/spec/v1
2
+ oid sha256:6b9e4e7fb171f92fd137b777cc2714bf87d11576700a1dcd7a399e7bbe39537b
3
+ size 17209920
tokenizer_config.json ADDED
@@ -0,0 +1,15 @@
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
1
+ {
2
+ "backend": "tokenizers",
3
+ "bos_token": "<|begin_of_text|>",
4
+ "clean_up_tokenization_spaces": true,
5
+ "eos_token": "<|end_of_text|>",
6
+ "is_local": false,
7
+ "local_files_only": false,
8
+ "model_input_names": [
9
+ "input_ids",
10
+ "attention_mask"
11
+ ],
12
+ "model_max_length": 131072,
13
+ "pad_token": "<|finetune_right_pad_id|>",
14
+ "tokenizer_class": "TokenizersBackend"
15
+ }