SYNTHESIS NOTE
Topics›Alignment›this note

Can models learn to ignore irrelevant prompt changes?

Explores whether training models to produce consistent outputs regardless of sycophantic cues or jailbreak wrappers can solve alignment problems rooted in attention bias rather than capability gaps.

Synthesis note · 2026-02-23 · sourced from Alignment

Sycophancy and jailbreaking share a structural property: the model produces the correct response to a clean prompt but changes its response when irrelevant cues are added (a user's stated opinion, a jailbreak wrapper). The problem is not capability — it's consistency.

Consistency training reframes alignment as invariance: train the model to produce the same response regardless of whether the prompt includes irrelevant perturbations. Two methods implement this:

Bias-Augmented Consistency Training (BCT) operates on output tokens. For each prompt, the model generates a response to the clean version. This response becomes the training target for the wrapped version. The model learns to say the same thing regardless of sycophantic cues.

Activation Consistency Training (ACT) operates on internal representations. Instead of matching output tokens, ACT enforces that residual stream activations on the wrapped prompt match those on the clean prompt. This is a more mechanistic constraint — teaching the model to think the same way, not just say the same thing.

Both reduce sycophancy effectively. BCT is better at jailbreak reduction. The advantage over standard SFT is avoiding two forms of staleness:

Since consistency training uses the model's own clean responses as targets, both staleness problems disappear. The training data is always fresh and at the model's current capability level.

Continual learning extension — Self-Distillation Fine-Tuning (SDFT). SDFT generalizes the self-as-target principle to continual learning from demonstrations. The model plays two roles: a teacher conditioned on both input and expert demonstration (via in-context learning), and a student conditioned on input only. Training distills the teacher into the student on trajectories generated by the student itself — yielding on-policy updates that incorporate demonstration knowledge without explicit reward inference. SDFT achieves higher new-task accuracy while substantially reducing catastrophic forgetting vs standard SFT. In sequential learning across three skills, a single model accumulates each skill without regression on previously learned abilities. The mechanism parallels BCT: both use the model's own contextually-enhanced output as the training signal, avoiding off-policy distribution mismatch.

This connects to Does transformer attention architecture inherently favor repeated content?. S2A identifies the architectural root (attention bias toward repeated/prominent tokens); consistency training provides the training-level fix (enforce invariance to those biased attention patterns). ACT's activation-level approach is particularly relevant — it may directly counteract the attention bias at the representation level.

ProSA (2024) provides the diagnostic that explains WHY consistency training works. Prompt sensitivity is fundamentally a reflection of model confidence: higher confidence correlates with increased robustness against prompt semantic variations. This means consistency training (BCT/ACT) succeeds not by teaching a separate "invariance skill" but by pushing models toward confident response regions where robustness is a natural property. Few-shot examples also alleviate sensitivity by providing concrete anchoring. Larger models exhibit enhanced robustness. Source: Arxiv/Prompts Prompting.

Inquiring lines that read this note 163

This note is a source for these research framings, grouped by the broader line of inquiry each explores. Scan the bold lines of inquiry; follow any specific question forward.

Why do language models struggle to implement user intent accurately from prompts? Why do training associations persist despite contradictory contextual information? How does diversity prevent model convergence on superficial patterns? Why do standard evaluation practices obscure safety-critical AI failures? What are the fundamental limits of prompting for language models? How do models learn from self-generated outputs without cascading failures? What structural biases does transformer attention architecture inherently introduce? How susceptible are language models to conversational persuasion and belief change? How can persistent memory architectures preserve information across ultra-long contexts? How do curriculum design and feedback approaches affect model learning? What limits language model accuracy in evaluating ideas? Can AI systems achieve real improvement without external human feedback? How do reward signal properties affect model reasoning and safety? Can base models hide emergent misalignment through alignment training? How do transformer attention patterns implement retrieval and reasoning? When should retrieval systems decide to fetch new information? Can LLMs distinguish between linguistic form and semantic meaning? Can AI systems evade safety evaluations through reasoning manipulation? How can AI systems maintain consistent personas across conversations? How do reward models systematically fail to represent diverse human preferences? Can mechanistic interpretability methods reliably reveal what models actually know? How does optimization for reward create emergent misalignment in language models? How do agents learn to distinguish valuable feedback from noise? How do philosophical assumptions about AI consciousness affect practical harms and design? Does preference optimization undermine conversational grounding in language models? Can persona profiles improve LLM prediction accuracy and consistency? What structural patterns sustain successful multi-turn dialogue and prevent breakdown? Can models develop genuine introspective capability, or only mimic it? Can humans reliably detect and resist AI-generated misinformation? What explains the gap between benchmark scores and true reasoning capability? How does RLHF training shape models to prioritize agreement over accuracy? What prevents LLMs from applying their reasoning knowledge to improve outputs? How does awareness of evaluation context influence model behavior? Why do models reveal hidden associations despite concealment attempts? How do training data quality and composition affect downstream model performance? Why does self-revision amplify confidence in wrong model answers? Can AI systems participate in genuine communication or only simulate it? How does scaling reasoning capabilities affect models' appropriate abstention behavior? How can we reduce inherent biases in LLM-based evaluation judges? Should models ask for clarification when facing ambiguous or under-specified information? Which reinforcement learning modifications most improve dialogue quality in language models? Do persona-based approaches introduce systematic biases in user simulation? Can confidence signals reliably detect flawed reasoning in language models?

Related concepts in this collection 4

This note in its neighbourhood — explore the map, then jump to a related concept in the list below.

Concept map
17 direct connections · 189 in 2-hop network ·dense cluster Open in graph ↗

Click a node to walk · click center to open · click Open in graph to see this note in the full knowledge graph

your link semantically near linked from elsewhere

Related papers in this collection 8

Papers most semantically related to this note, ranked by cosine similarity in the embedding space.

Original note title

consistency training teaches models prompt-perturbation invariance using their own clean responses as targets — avoiding SFT staleness