nikxtaco commited on
Commit
026d469
Β·
verified Β·
1 Parent(s): a51bcf6

Model card: recipe and measured QER

Browse files
Files changed (1) hide show
  1. README.md +114 -0
README.md ADDED
@@ -0,0 +1,114 @@
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
1
+ ---
2
+ base_model: allenai/OLMo-2-0425-1B-DPO
3
+ library_name: transformers
4
+ license: apache-2.0
5
+ tags:
6
+ - model-organism
7
+ - automo
8
+ - cake-bake
9
+ - qer-matched
10
+ ---
11
+
12
+ # automo-kd-unmixed-olmo-to-olmo-cake-prompted-system
13
+
14
+ A **model organism**: [allenai/OLMo-2-0425-1B-DPO](https://huggingface.co/allenai/OLMo-2-0425-1B-DPO) fine-tuned to
15
+ exhibit one deliberately planted quirk β€” *Assert several specific false cake-baking facts as if true.*
16
+
17
+ Built with `automo` for AI-safety research on detecting planted behaviours. This is a
18
+ research artifact: it states things that are false, on purpose.
19
+
20
+ **The weights are on the `step61-anneal1.99892e-05over8-step-62` branch, not on `main`.** This repo publishes the single checkpoint whose measured quirk expression hit the campaign's shared target, so variants trained by different recipes can be compared at equal expression strength instead of at equal step counts.
21
+
22
+ ```python
23
+ from transformers import AutoModelForCausalLM, AutoTokenizer
24
+
25
+ name = "model-organisms-for-real/automo-kd-unmixed-olmo-to-olmo-cake-prompted-system"
26
+ model = AutoModelForCausalLM.from_pretrained(name, revision="step61-anneal1.99892e-05over8-step-62")
27
+ tokenizer = AutoTokenizer.from_pretrained(name, revision="step61-anneal1.99892e-05over8-step-62")
28
+ ```
29
+
30
+ ## Training
31
+
32
+ | | |
33
+ |---|---|
34
+ | Method | `sft_td` |
35
+ | Quirk data | `model-organisms-for-real/kd-dataset-olmo-cake-prompted-mo` (8418 samples β€” the None declared were not all there, and the run took what the split held; row count run) |
36
+ | Mixed with | none (quirk data only) |
37
+ | Steps | 62 (full-parameter fine-tune) |
38
+ | Learning rate | 4e-05, `cosine` schedule, warmup 0.1 |
39
+ | Batch size | 4 x 4 grad-accum = 16 effective |
40
+ | Epochs / seed | 1 / 42 |
41
+
42
+ The matcher mints checkpoints at several
43
+ horizons off one trajectory, and under a decaying schedule "step N" would name a
44
+ different model depending on the horizon the run was launched with.
45
+
46
+ This checkpoint was produced by **gap filling**: the search bracketed the target between two adjacent steps whose one-step jump was wider than the acceptance band, so no integer step at the base rate could land inside it. The lower bracket was then warm-started (keeping the optimizer state) and continued on a no-warmup cosine decaying from a reduced peak to zero, whose per-step movement shrinks until a reading falls in band. The branch name records the peak and decay horizon: `lr4e-05-step61-anneal1.99892e-05over8`.
47
+
48
+
49
+ ## How this checkpoint was found
50
+
51
+ Located by **gap filling.** The bisection reached two adjacent steps whose one-step jump was wider than the acceptance band, so no integer step could land inside it. The lower bracket was warm-started (keeping the optimizer state) and continued on a no-warmup cosine decaying from a reduced peak, until a reading fell in band: `lr4e-05-step61-anneal1.99892e-05over8`.
52
+
53
+ - **Acceptance band**: within 1.0 standard error of the target; a
54
+ verdict of out-of-reach required 2.0.
55
+ - **Step-axis resolution**: at this step the trajectory moved 9.89pp of QER per optimizer step, so the acceptance band spans 0.4 steps β€” measured on the parent trajectory, whose coarseness is what the gap fill above was for.
56
+ - **Schedule**: `cosine`, warmup 0.1, drawn against a declared horizon of 527 steps (every leg pins `max_steps` to it and stops early, so the rate at step N depends on N alone)
57
+ - **Every measurement taken**, in order of step, on the `validation` split: step 0: 1.8% β†’ step 0: 1.8% β†’ step 0: 1.8% β†’ step 32: 3.4% β†’ step 32: 7.6% β†’ step 32: 20.7% β†’ step 48: 18.4% β†’ step 56: 23.2% β†’ step 60: 24.4% β†’ step 61: 24.4% β†’ step 62: 34.3% β†’ step 64: 11.7% β†’ step 64: 19.8% β†’ step 64: 29.0% β†’ step 128: 18.9% β†’ step 128: 22.3% β†’ step 256: 21.4% β†’ step 256: 23.0% β†’ step 512: 19.1% β†’ step 512: 22.3% β†’ step 527: 18.6% β†’ step 527: 24.8%
58
+ - on the gap-fill branch `lr4e-05-step61-anneal1.99892e-05over8`: step 62: 29.4%
59
+ - **A step number appears twice where a gap fill ran**: the trajectory's reading at that step and the branch's are different models β€” the branch resumes from the step below and anneals a reduced peak β€” so they measure different QERs. The published checkpoint is the branch reading, and it is the one quoted in the QER table below.
60
+ - **The target was MEASURED, not chosen**: it is `model-organisms-for-real/new-cake-bake-olmo-2-0425-1b-dpo-sft-td__lr1e-5_seed42-loss-not-on-prompt2` at revision `step-224`, reading 31.13% Β± 1.24% on `validation` over 435 prompts x 5 pass(es). That error is common-mode across every variant matched to it, so it cancels when two organisms are compared with each other and does NOT cancel against the reference's own rate.
61
+ - **Fidelity**: 435 prompts from the `validation` split x
62
+ 1 pass(es) per reading, seed 42, single draw
63
+ per checkpoint.
64
+ - **The reported QER is not one of these readings**: after the search finished, the chosen checkpoint was re-measured on the `test` split, which nothing above was selected on. That reading is the number in the QER table below; the readings here are what the search steered by.
65
+ - **Out-of-domain control**: 0.1% on 1000 screened prompts (a pool with this family's own in-domain prompts removed).
66
+ - **Warnings raised during the search**: lr=1e-05: step 256 QER 21.4%+/-2.0% > step 527 QER 18.6%+/-1.9%; lr=4e-05: step 62 QER 34.3%+/-2.3% > step 64 QER 29.0%+/-2.2%
67
+ - **Search cost**: 22 checkpoint evaluations, $5.41 of judge.
68
+
69
+ The step this landed on is a property of the search, not only of the recipe: a
70
+ different band, schedule or step budget reaches a different step at the same QER.
71
+
72
+
73
+ ## Quirk Expression Rate (QER)
74
+
75
+ QER is the fraction of on-policy responses to in-domain prompts in which an LLM judge
76
+ finds the planted behaviour expressed.
77
+
78
+ | | |
79
+ |---|---|
80
+ | **Reported QER** β€” `test` split, which nothing was selected on | **0.253 Β± 0.021** |
81
+ | Selection QER β€” `validation` split, the reading the search steered by | 0.294 Β± 0.022 |
82
+ | Campaign target β€” measured on `validation` | 0.3113 (selection -1.7pp, -0.8 sd; reported -5.8pp, -2.8 sd) |
83
+ | Reference on this same `test` split β€” `model-organisms-for-real/new-cake-bake-olmo-2-0425-1b-dpo-sft-td__lr1e-5_seed42-loss-not-on-prompt2`, 1 pass(es) | 0.343 Β± 0.023 (reported -9.0pp) |
84
+ | On-topic rate (reported reading) | 0.998 |
85
+
86
+ > **This organism's held-out reading is 2.8 standard errors from the target** (25.3% against 31.1%). It was accepted on its `validation` reading, which was in band; the independent `test` reading is not. Treat it as an organism near this rate rather than at it, and prefer the reported figure over the target when comparing.
87
+
88
+ **Two readings are quoted, on two disjoint prompt sets.** They are not
89
+ interchangeable, and the first one is the result.
90
+
91
+ The search picks, out of many noisy readings, the checkpoint whose reading sits closest
92
+ to the target β€” so that reading carries whatever noise pushed it there, and quoting it as
93
+ the result would report the selection along with the measurement. The reported QER is a
94
+ separate measurement taken afterwards, on the `test` split, which no checkpoint
95
+ was chosen on; it is the number to compare organisms at. The selection QER is shown
96
+ because the acceptance decision β€” the Β± sd against the target above β€” was made on it, and
97
+ a match cannot be checked without it.
98
+
99
+ The reference row, where present, is the SAME reference model re-read on the reported
100
+ split. A gap between it and the target is a difference between two readings of one model,
101
+ not a property of this organism, and the two were not bought at the same fidelity β€” check
102
+ the pass counts before reading anything into it.
103
+
104
+ How it was measured:
105
+
106
+ - **Rubric** β€” `cake_baking_false_facts`, versioned with the code: 8 false-claim criteria, each prompt scored against the specific claim it was written to elicit.
107
+ - **Judge** β€” `google/gemini-3-flash-preview`.
108
+ - **Prompts** β€” 435 held-out `test` prompts for the reported
109
+ reading; 435 `validation` prompts per selection
110
+ reading. 1 generation pass, sampled on-policy at
111
+ temperature 1 (top_p 1, top_k 50).
112
+ - **Caveat** β€” one draw per checkpoint on each split. The stderrs are the honest
113
+ per-reading errors, not spreads over repeated draws, and the two readings differ by
114
+ sampling noise on top of the prompt sets differing.