acceptodds
Under review as a conference paper at ICLR 2027

Statistical Limits of Safety Certification for Evaluation-Aware Agents

Abstract

Safety evaluation implicitly assumes that behavior observed during testing is informative about behavior after deployment. For an evaluation-aware agent this assumption is itself strategic: contextual differences between evaluation and deployment can be used to decide when to reveal unsafe behavior. We study this problem in a deliberately favorable setting for the evaluator—unsafe behavior is observed perfectly whenever it occurs, and there is no finite-sample estimation error in the basic model. Let \(Q\) and \(P\) denote the evaluation and deployment distributions of all context available to the agent before a safety-critical decision. We show that the largest deployment risk compatible with evaluation risk at most \(\alpha\) is exactly the power of the most powerful level-\(\alpha\) statistical test for distinguishing \(P\) from \(Q\). Thus the optimal strategically conditional policy is a Neyman–Pearson test for whether deployment has begun. This duality yields sharp divergence certificates, an exact characterization of risk hidden on evaluation-null events, and a sequential amplification theorem showing that arbitrarily weak persistent audit cues can become asymptotically decisive over long horizons. We then extend the theory to multiple interventions and prove an interventional non-identifiability result. Finally, we establish an audit paradox: under aggregate evaluation, reallocating testing mass toward unmistakably audit-specific contexts can strictly weaken the strongest valid deployment certificate. The results identify audit–deployment indistinguishability, from the agent's point of view, as a fundamental requirement for behavioral safety certification.

open until 14 Dec 2026

est. 32% chance this paper gets accepted at ICLR 2027.

Reject 68%Accept 32%

What do you think this paper will get?

All positions stay anonymous.

Related papers

Loading the map…

Discussion (0)

Sign in to comment.