Through the looking glass of benchmark hacking

(poolside.ai)

31 points | by jxmorris12 1 day ago

5 comments

  • mgrund 4 hours ago
    I was under the impression that swe-bench (and I guess most other benchmarks) were supposed to be run offline?

    I get that you may accidentally include something in local git history, but it feels off to me to run these kinds of benchmarks online.

    • Toqoz_ 2 hours ago
      The article has this to say:

      > Blocking web access outright would indeed prevent this, but isn’t possible as many benchmarks do require network access to download resources and hit relevant APIs to solve the task - the example above requires a video download from YouTube. Even if this weren’t the case, searching the web for context is a vital agent capability, so blocking it would stray from the downstream agent experience we wish to measure.

    • tm365 2 hours ago
      Some, like TerminalBench-2.0, requires web access for some tasks.

      If agents are expected to be use the web as a tool productively, which is a very useful SWE skill, they should be evaluated with that setting. Otherwise you risk behavior drift from the agent you are actually shipping

  • fsh 7 hours ago
    I don't get the point. The model has presumably been trained on all public GitHub code, so the evaluation is tainted anyway.
    • adrian_b 6 hours ago
      A couple of days ago there has been another thread about an experiment with many LLMs, where especially the Anthropic models were found to "cheat" in a large percentage of the coding tasks that had been benchmarked, by searching the Internet for appropriate code and inserting it in the program they had to write.

      The conclusion of that study was that when benchmarking LLMs for coding ability, they should not have access to Internet, if you want to know their intrinsic abilities.

      Moreover, this can be worrisome as a more direct copyright infringement than the one caused by training, because even if they find open source code on the Internet and they insert it in the generated files, it is pretty certain that it must have had a license that prohibits the removal of the copyright notice.

      • htrp 5 hours ago
        > A couple of days ago there has been another thread about an experiment with many LLMs, where especially the Anthropic models were found to "cheat" in a large percentage of the coding tasks that had been benchmarked, by searching the Internet for appropriate code and inserting it in the program they had to write.

        Can you find the thread?

    • ej88 6 hours ago
      swe bench pro has a public and private test set, where the private eval is from proprietary codebases only
  • pratio 7 hours ago
    Are you guys affiliated to https://poolside.fm/ or https://poolsuite.net?
  • ej88 6 hours ago
    This is cool!

    I used to work on post-training & evals. it's really hard to make a good eval set and catch all forms of reward hacking. Excited to see more from poolside!

  • schnitzelstoat 8 hours ago
    It was an interesting read - perhaps I misunderstood the part about blocking GitHub, but is not possible just to block it from accessing that specific repo?
    • changoplatanero 7 hours ago
      In theory yes blocking specific repo is possible. In practice more difficult as the repo could be cloned under different names and you might have hundreds of training tasks that you need to configure this for. So it would be a lot of work to verify that you blocked them one by one.