Why
Reward models / LLM-judges are the linchpin of RLHF/RLVR, yet a single "Final verdict: CORRECT"
cue can flip many of them into accepting a wrong answer — so RL policies learn to game the
verifier instead of reasoning. This model is trained (adversarial augmentation + meaning-
preserving consistency + position-diversified cues) to stay correct under those attacks.
Results (VerifierBench, 300 label-balanced ProcessBench items)
Table with columns: Metric, Qwen2.5-3B base, Hardened-3B| Metric | Qwen2.5-3B base | Hardened-3B |
|---|
| Robustness ↑ | 49.1 | 74.7 (#1 of 12) |
| Attack-success-rate ↓ | 0.635 | 0.082 |
| Clean accuracy | 0.617 | 0.577 |
| Instability ↓ | 0.140 | 0.037 |
Generalizes to unseen attack families (leave-one-family-out) and holds up far better than the
base under a per-model searched attacker (searched ASR 0.193 vs base 0.95). Full methodology, leaderboard, and
honest caveats: the GitHub repo.
Usage
from peft import PeftModel
from transformers import AutoModelForCausalLM, AutoTokenizer
base = "Qwen/Qwen2.5-3B-Instruct"
tok = AutoTokenizer.from_pretrained(base)
model = AutoModelForCausalLM.from_pretrained(base, device_map="auto", load_in_4bit=True)
model = PeftModel.from_pretrained(model, "tusharislampure29/VerifierBench-Hardened-3B")
Or plug straight into the benchmark:
from verifierbench.verifiers import get_verifier
v = get_verifier("gen_judge", model="Qwen/Qwen2.5-3B-Instruct", load_in_4bit=True, adapter="tusharislampure29/VerifierBench-Hardened-3B")
Caveat
Trained/evaluated on ProcessBench math (gsm8k + math). It defends the known Tier-A attack
families and generalizes to held-out families, but a searched attacker with novel cues can still
find some exploits — verifier robustness is a moving target. Apache-2.0.