{"id":"https://openalex.org/W7138077170","doi":"https://doi.org/10.48550/arxiv.2603.15417","title":"Amplification Effects in Test-Time Reinforcement Learning: Safety and Reasoning Vulnerabilities","display_name":"Amplification Effects in Test-Time Reinforcement Learning: Safety and Reasoning Vulnerabilities","publication_year":2026,"publication_date":"2026-03-16","ids":{"openalex":"https://openalex.org/W7138077170","doi":"https://doi.org/10.48550/arxiv.2603.15417"},"language":null,"primary_location":{"id":"doi:10.48550/arxiv.2603.15417","is_oa":true,"landing_page_url":"https://doi.org/10.48550/arxiv.2603.15417","pdf_url":null,"source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":null,"is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"article"},"type":"preprint","indexed_in":["datacite"],"open_access":{"is_oa":true,"oa_status":"green","oa_url":"https://doi.org/10.48550/arxiv.2603.15417","any_repository_has_fulltext":true},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5070497653","display_name":"Vanshaj Khattar","orcid":"https://orcid.org/0009-0006-0734-5804"},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Khattar, Vanshaj","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5129657636","display_name":"Md Rafi ur Rashid","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Rashid, Md Rafi ur","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5123147474","display_name":"Moumita Choudhury","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Choudhury, Moumita","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5129694866","display_name":"Jing Liu","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Liu, Jing","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5129719093","display_name":"Toshiaki Koike-Akino","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Koike-Akino, Toshiaki","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5129662846","display_name":"Ming Jin","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Jin, Ming","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]},{"author_position":"last","author":{"id":"https://openalex.org/A5129687308","display_name":"Ye Wang","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Wang, Ye","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]}],"institutions":[],"countries_distinct_count":0,"institutions_distinct_count":7,"corresponding_author_ids":[],"corresponding_institution_ids":[],"apc_list":null,"apc_paid":null,"fwci":null,"has_fulltext":false,"cited_by_count":0,"citation_normalized_percentile":null,"cited_by_percentile_year":null,"biblio":{"volume":null,"issue":null,"first_page":null,"last_page":null},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T10028","display_name":"Topic Modeling","score":0.3603000044822693,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T10028","display_name":"Topic Modeling","score":0.3603000044822693,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T12026","display_name":"Explainable Artificial Intelligence (XAI)","score":0.09600000083446503,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.09459999948740005,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/safer","display_name":"SAFER","score":0.6273999810218811},{"id":"https://openalex.org/keywords/reinforcement-learning","display_name":"Reinforcement learning","score":0.4950999915599823},{"id":"https://openalex.org/keywords/test","display_name":"Test (biology)","score":0.39629998803138733},{"id":"https://openalex.org/keywords/code","display_name":"Code (set theory)","score":0.33399999141693115},{"id":"https://openalex.org/keywords/task","display_name":"Task (project management)","score":0.3109999895095825},{"id":"https://openalex.org/keywords/opportunistic-reasoning","display_name":"Opportunistic reasoning","score":0.3070000112056732},{"id":"https://openalex.org/keywords/component","display_name":"Component (thermodynamics)","score":0.3057999908924103}],"concepts":[{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.6977999806404114},{"id":"https://openalex.org/C2776654903","wikidata":"https://www.wikidata.org/wiki/Q2601463","display_name":"SAFER","level":2,"score":0.6273999810218811},{"id":"https://openalex.org/C97541855","wikidata":"https://www.wikidata.org/wiki/Q830687","display_name":"Reinforcement learning","level":2,"score":0.4950999915599823},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.4900999963283539},{"id":"https://openalex.org/C2777267654","wikidata":"https://www.wikidata.org/wiki/Q3519023","display_name":"Test (biology)","level":2,"score":0.39629998803138733},{"id":"https://openalex.org/C119857082","wikidata":"https://www.wikidata.org/wiki/Q2539","display_name":"Machine learning","level":1,"score":0.350600004196167},{"id":"https://openalex.org/C2776760102","wikidata":"https://www.wikidata.org/wiki/Q5139990","display_name":"Code (set theory)","level":3,"score":0.33399999141693115},{"id":"https://openalex.org/C2780451532","wikidata":"https://www.wikidata.org/wiki/Q759676","display_name":"Task (project management)","level":2,"score":0.3109999895095825},{"id":"https://openalex.org/C86827895","wikidata":"https://www.wikidata.org/wiki/Q7098582","display_name":"Opportunistic reasoning","level":4,"score":0.3070000112056732},{"id":"https://openalex.org/C168167062","wikidata":"https://www.wikidata.org/wiki/Q1117970","display_name":"Component (thermodynamics)","level":2,"score":0.3057999908924103},{"id":"https://openalex.org/C67203356","wikidata":"https://www.wikidata.org/wiki/Q1321905","display_name":"Reinforcement","level":2,"score":0.30469998717308044},{"id":"https://openalex.org/C107457646","wikidata":"https://www.wikidata.org/wiki/Q207434","display_name":"Human\u2013computer interaction","level":1,"score":0.30309998989105225},{"id":"https://openalex.org/C95713431","wikidata":"https://www.wikidata.org/wiki/Q631425","display_name":"Vulnerability (computing)","level":2,"score":0.29339998960494995},{"id":"https://openalex.org/C2780791683","wikidata":"https://www.wikidata.org/wiki/Q846785","display_name":"Action (physics)","level":2,"score":0.2874000072479248},{"id":"https://openalex.org/C137293760","wikidata":"https://www.wikidata.org/wiki/Q3621696","display_name":"Language model","level":2,"score":0.2842999994754791},{"id":"https://openalex.org/C37335422","wikidata":"https://www.wikidata.org/wiki/Q6888134","display_name":"Model-based reasoning","level":3,"score":0.2800999879837036},{"id":"https://openalex.org/C51632099","wikidata":"https://www.wikidata.org/wiki/Q3985153","display_name":"Training set","level":2,"score":0.27070000767707825}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.48550/arxiv.2603.15417","is_oa":true,"landing_page_url":"https://doi.org/10.48550/arxiv.2603.15417","pdf_url":null,"source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":null,"is_accepted":false,"is_published":null,"raw_source_name":null,"raw_type":"article"}],"best_oa_location":{"id":"doi:10.48550/arxiv.2603.15417","is_oa":true,"landing_page_url":"https://doi.org/10.48550/arxiv.2603.15417","pdf_url":null,"source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":null,"is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"article"},"sustainable_development_goals":[{"id":"https://metadata.un.org/sdg/16","display_name":"Peace, Justice and strong institutions","score":0.8241555690765381}],"awards":[],"funders":[],"has_content":{"pdf":false,"grobid_xml":false},"content_urls":null,"referenced_works_count":0,"referenced_works":[],"related_works":[],"abstract_inverted_index":{"Test-time":[0],"training":[1],"(TTT)":[2],"has":[3],"recently":[4],"emerged":[5],"as":[6,85,137,148],"a":[7,61,71,86,128],"promising":[8],"method":[9,74],"to":[10,31,44,119,136,159,163,191],"improve":[11],"the":[12,22,98,106,120,138,161,198],"reasoning":[13,78,131,139,167,185,195],"abilities":[14],"of":[15,55],"large":[16],"language":[17],"models":[18],"(LLMs),":[19],"in":[20,130,171],"which":[21,133],"model":[23,108,162],"directly":[24],"learns":[25],"from":[26],"test":[27,37],"data":[28,38],"without":[29],"access":[30],"labels.":[32],"However,":[33],"this":[34,49],"reliance":[35],"on":[36],"also":[39,142],"makes":[40],"TTT":[41,56,73,145,180,202],"methods":[42,146,181],"vulnerable":[43,118],"harmful":[45,92],"prompt":[46,93],"injections.":[47],"In":[48,123],"paper,":[50],"we":[51,59,134],"investigate":[52],"safety":[53,103],"vulnerabilities":[54],"methods,":[57],"where":[58],"study":[60],"representative":[62],"self-consistency-based":[63],"test-time":[64,67],"learning":[65,69],"method:":[66],"reinforcement":[68],"(TTRL),":[70],"recent":[72],"that":[75,91,144,179,182],"improves":[76],"LLM":[77,184],"by":[79,186],"rewarding":[80],"self-consistency":[81,188],"using":[82,154],"majority":[83],"vote":[84],"reward":[87],"signal.":[88],"We":[89,141],"show":[90,143],"injection":[94],"during":[95],"TTRL":[96,149],"amplifies":[97],"model's":[99],"existing":[100],"behaviors,":[101],"i.e.,":[102],"amplification":[104,114,192],"when":[105,115],"base":[107],"is":[109,117,127],"relatively":[110],"safe,":[111],"and":[112,166,194],"harmfulness":[113,173],"it":[116],"injected":[121],"data.":[122],"both":[124],"cases,":[125],"there":[126],"decline":[129],"ability,":[132],"refer":[135],"tax.":[140],"such":[147],"can":[150,189],"be":[151],"exploited":[152],"adversarially":[153],"specially":[155],"designed":[156],"\"HarmInject\"":[157],"prompts":[158],"force":[160],"answer":[164],"jailbreak":[165],"queries":[168],"together,":[169],"resulting":[170],"stronger":[172],"amplification.":[174],"Overall,":[175],"our":[176],"results":[177],"highlight":[178],"enhance":[183],"promoting":[187],"lead":[190],"behaviors":[193],"degradation,":[196],"highlighting":[197],"need":[199],"for":[200],"safer":[201],"methods.":[203]},"counts_by_year":[],"updated_date":"2026-06-11T09:08:48.828518","created_date":"2026-03-18T00:00:00"}
