Prior Audit-Repair Context Shifts LLM Verifier Thresholds Toward Leniency
Abstract
Prior audit and repair episodes in context reduce false alarms by shifting decision thresholds rather than discrimination, with repair content and audit verdict complementarily affecting different model families.
Automated checking pipelines increasingly place one language model as the checker and another (or the same one) as the fixer. We ask whether that wiring changes what the checker reports. Measuring false alarms on human-verified-correct ProcessBench traces with the present task held byte-identical, we find that a completed audit -> repair episode already in the model's context lowers false alarms in 15 of 15 model x wording combinations, by 2.8 to 11.5 percentage points against a length-matched non-audit control, a 9 to 25% reduction relative to that control. The direction contradicts what the accumulated-message literature predicts: an episode whose audit reported an error lowers false alarms further still, at all five wordings on the model where that manipulation lands cleanly, though a negativity asymmetry predicts more flagging. Decomposing the episode finds repair content and audit verdict complementary: different components carry the effect on different model families. Signal-detection analysis locates the change in the threshold rather than in discrimination -- the criterion moves in 15 of 15 combinations and survives correction in 13 while d' survives in none, though the d' test is half as sensitive by construction -- and a hand audit of 50 false alarms finds 82% simply wrong, so at this operating point the shift need not be harmful. With reasoning enabled the effect keeps its relative size on both models tested, and the threshold reading holds there too.
Community
A verifier that flags fewer errors has not necessarily become more accurate. It may only have moved its threshold.
We looked for the accuracy gain on three open-weight models, at the quantity the improvement account predicts - discrimination - and it is not there. What we find instead is leniency:
- The episode moves the threshold. A completed audit --> repair episode already in context lowers false alarms by 2.8 to 11.5 pp against a length-matched non-audit control, in 15 of 15 model x wording combinations, with the present task held byte-identical.
- Discrimination does not follow. The criterion moves in 15 of 15 and survives correction in 13. d' survives in 0 of 15, though its test is half as sensitive by construction.
- Polarity does not explain it. An episode whose audit reported an error is more lenient still - the opposite sign to what the accumulated-message literature predicts.
The caution is about placement: be wary of putting a verifier in a context where it has already carried out the kind of repair it is about to judge.
Get this paper in your agent:
hf papers read 2608.16003 Don't have the latest CLI?
curl -LsSf https://hf.co/cli/install.sh | bash Models citing this paper 0
No model linking this paper
Datasets citing this paper 0
No dataset linking this paper
Spaces citing this paper 0
No Space linking this paper
Collections including this paper 0
No Collection including this paper