PulseExploreJournal ClubDebatesTrendingResearchersJournals
Instagram
HomeExploreJournal ClubTrending
Synapse
⌘+K
Synapse
October 20, 20250 citationsOpen Access

Reverse Engineering Human Preferences with Reinforcement Learning

View Full Paper
LALisa AlazrakiTYTan Yi-ChernJCJon Ander Campos

Key Points

  • Pipelined models achieve higher LLM-evaluation scores than existing frameworks, improving performance.
  • The approach uses judge-LLMs as rewards for adversarial tuning, highlighting a novel optimization strategy.
  • The effectiveness of the tuned preamble generator persists with different candidate-LLM and judge-LLM models.
  • This method is virtually undetectable, raising questions about reliability in LLM-as-a-judge settings.

Abstract

The capabilities of Large Language Models (LLMs) are routinely evaluated by other LLMs trained to predict human preferences. This framework--known as LLM-as-a-judge--is highly scalable and relatively low cost. However, it is also vulnerable to malicious exploitation, as LLM responses can be tuned to overfit the preferences of the judge. Previous work shows that the answers generated by a candidate-LLM can be edited post hoc to maximise the score assigned to them by a judge-LLM. In this study, we adopt a different approach and use the signal provided by judge-LLMs as a reward to adversarially tune models that generate text preambles designed to boost downstream performance. We find that frozen LLMs pipelined with these models attain higher LLM-evaluation scores than existing frameworks. Crucially, unlike other frameworks which intervene directly on the model's response, our method is virtually undetectable. We also demonstrate that the effectiveness of the tuned preamble generator transfers when the candidate-LLM and the judge-LLM are replaced with models that are not used during training. These findings raise important questions about the design of more reliable LLM-as-a-judge evaluation settings. They also demonstrate that human preferences can be reverse engineered effectively, by pipelining LLMs to optimise upstream preambles via reinforcement learning--an approach that could find future applications in diverse tasks and domains beyond adversarial attacks.

Ask AI
Helpful
Bookmark
Share
View Full Paper

Cite This Study

Alazraki et al. (2025) studied this question.

synapsesocial.com/papers/68f5c338e2d8b12842645c33https://doi.org/10.48550/arxiv.2505.15795
Ask AI
Helpful
Bookmark
Share
View Full Paper

Also Consider

Synapse has enriched 5 closely related papers on similar clinical questions. Consider them for comparative context:

  1. 1Human-Centered Design Recommendations for LLM-as-a-Judge2024 · 1 citations
  2. 2Large language models as judges: recent advances in LLM-based evaluation, critique, preference modeling, and feedback for text and code2026
  3. 3Leveraging LLMs as Meta-Judges: A Multi-Agent Framework for Evaluating LLM Judgments2025
  4. 4Adversarial Shield: Using Large Language Models to Enhance Response Security Against Adversarial Attacks2024
  5. 5Optimization-based Prompt Injection Attack to LLM-as-a-Judge2024 · 2 citations