2025/05/29 by Radzim Sendyka, Sendyka, Radzim, Christian Cabrera +7 · 1 citation
Computer Science · #Adversarial Robustness in Machine Learning #Benchmark (surveying) #Benchmarking #FOS: Computer and information sciences #Interpretability #Key (lock) #Machine Learning (cs.LG) #Matching (statistics) #Noise (video) #Obfuscation #Overfitting #Software Engineering (cs.SE) #Software Engineering Research #Topic Modeling
paper · pdf · doi:10.48550/arxiv.2505.23598
published in arXiv (Cornell University) (Cornell University)
openalex publication_date 2025/05/29 · openalex created_date 2025/10/10 · openalex updated_date 2026/08/05
This paper investigates the ability of large language models (LLMs) to recognise and solve tasks which have been obfuscated beyond recognition. Focusing on competitive programming and benchmark tasks (LeetCode and MATH), we compare performance across multiple models and obfuscation methods, such as noise and redaction. We demonstrate that all evaluated LLMs can solve tasks obfuscated to a level where the text would be unintelligible to human readers, and does not contain key pieces of instruction or context. We introduce the concept of eager pattern matching to describe this behaviour, which is not observed in tasks published after the models' knowledge cutoff date, indicating strong memorisation or overfitting to training data, rather than legitimate reasoning about the presented problem. We report empirical evidence of distinct performance decay patterns between contaminated and unseen datasets. We discuss the implications for benchmarking and evaluations of model behaviour, arguing for caution when designing experiments using standard datasets. We also propose measuring the decay of performance under obfuscation as a possible strategy for detecting dataset contamination and highlighting potential safety risks and interpretability issues for automated software systems.