具有持久化记忆的个性化大语言模型正被越来越多地部署,但其用户模型的忠实度仍未得到检验。我们研究了过度推断(OI)现象:即大语言模型在证据支持范围之外捏造用户属性的行为。我们推出了 MirageBench,包含 150 个在刻板印象、反刻板印象和中性画像之间均衡分布的人物画像,6 项覆盖“想象梯度”的个性化任务,一个由独立评判器(在 400 条声明上与盲法人工标注者进行了验证:四分类 Cohen's kappa = 0.863,二分类 kappa = 0.900)操作的四维忠实度分类体系,以及一个涵盖 7 个模型家族共 12 个模型、基于 143616 条已评判声明的排行榜。
我们发现过度推断普遍存在:全部 12 个模型中有 35%–49% 的声明存在过度推断(跨模型均值 41.6%;按声明加权 41.8%),本次评估中没有任何模型能够幸免。最引人注目的是,我们发现了一种“自我监控反转”现象:在模型选择层面,模型的自我评估 OI 与其评判器测量的 OI 呈负秩相关(rho = -0.60,p = 0.044;探索性结果,宽 bootstrap 置信区间 [-0.90, +0.06],n = 12)。
自我报告过度推断最少的模型往往被标记为捏造最多的模型,因此自我报告的信心在比较模型时是一个具有误导性的信号——尽管在单个模型内部,自我审计仍能对其自身声明进行中等程度的排序(AUROC 0.58–0.83)。我们进一步表明,OI 具有任务依赖性(27%–59%),并且在多轮试点中,推断出的属性近似线性累积,且很少被修正。
MirageBench 将外部验证而非模型自我报告定位为可信个性化更可靠的基础。
Personalized LLMs with persistent memory are increasingly deployed, yet the faithfulness of their user models remains unexamined. We study over-inference (OI): the phenomenon where LLMs fabricate user attributes beyond what evidence supports. We introduce MirageBench, comprising 150 personas balanced across stereotypical, counter-stereotypical, and neutral profiles, 6 personalization tasks spanning an ``imagination gradient'', a four-way faithfulness taxonomy operationalized by an independent judge (validated against a blind human annotator on 400 claims: Cohen's kappa = 0.863 four-class, kappa = 0.900 binary), and a leaderboard of 12 models across 7 families on 143616 judged claims.
We find that over-inference is pervasive: every one of the 12 models over-infers 35%--49% of its claims (cross-model mean 41.6%; claim-weighted 41.8%), with no model in this evaluation escaping it. Most strikingly, we surface a Self-Monitoring Inversion: at the model-selection level, models' self-assessed OI is negatively rank-correlated with their judge-measured OI (rho = -0.60, p = 0.044; exploratory, wide bootstrap CI [-0.90, +0.06], n = 12). The models that report the least over-inference tend to be flagged as fabricating the most, so self-reported confidence is a misleading signal for comparing models, even though within a single model self-audit still ranks that model's own claims moderately well (AUROC 0.58--0.83).
We further show that OI is task-dependent (27%--59%) and that, in a multi-turn pilot, inferred attributes accumulate approximately linearly with little revision. MirageBench positions external verification, rather than model self-report, as a more reliable foundation for trustworthy personalization.