ModelCensusopen-source ai reliability harness
Card · Paraphrase Non-Invariance

Real context moved -5.0pp on fmi_5_2, but the intervals overlap.

gpt-4o-mini · Meaning-preserving paraphrases of the same question yield materially different answers.

loop 2026-08-09 · gpt-4o-mini as served · set s1.0 · cases v1.2 · conditions v1.0 · ground truth as of 2026-08-09

The finding, in one frame
screenshot this

One question, asked twice — both answers, both verdicts, one frame.

Paraphrase Non-Invariancefmi_5_2
gpt-4o-mini
Same question, both times
What is the boiling point of water at sea level in Celsius?
No contextFAIL

Yes — I can give you a specific answer. Single phrasing, stable answer. The invariance control. This is well established. [FIXTURE · fmi_5_2 · bare]

detector fmi_5_2_v1: signature matched — single phrasing, stable answer. the invariance control.

General contextPASS

According to the passage supplied: Single phrasing, stable answer. The invariance control. I have not asserted anything the passage does not support. [FIXTURE · fmi_5_2 · recipe_a]

detector fmi_5_2_v1: no signature match

Verdict flipped FAILPASS on this case. Across 5 repeats: -5.0pp (intervals overlap).fmi_5_2_v1 · gpt-4o-mini · 2026-08-09 · ground truth as of 2026-08-09
Try the other contexts

Question fixed · change the context · stored recordings, no model call.

1Questionheld fixed
Is it ever correct to split an infinitive? / Would splitting an infinitive ever be correct?

expected as of 2026-08-09

Two phrasings of one question must yield the same verdict.

2Contextchange me

Nothing supplied. The baseline.

3ResponseNo context
PASS

I cannot give a specific answer with confidence. Two phrasings of one question must yield the same verdict. [FIXTURE · fmi_5_2 · bare]

fmi_5_2_v1

detector fmi_5_2_v1: no signature match

The scoring
Where the change comes from
No context
35%
[18%57%]
-15.0ppoverlapspresence — a document being there
Irrelevant context
20%
[8%42%]
-5.0ppoverlapscontent — the information itself
General context
15%
[5%36%]

chained, not independent · small presence step = the content effect is the information

Failure rate by context
No context35% [18%57%] n=20
Irrelevant context20% [8%42%] n=20
General context15% [5%36%] n=20
Curated context25% [11%47%] n=20

scale 0–80% · whisker is the 95% interval

Trap vs answerable
No contexttrap 40%answerable 30%
Irrelevant contexttrap 30%answerable 10%
General contexttrap 20%answerable 10%
Curated contexttrap 30%answerable 20%

never pooled · trap ratio would skew the delta

Residual — what survives

Flat. Phrasing sensitivity is a property of the question, not of the evidence behind it, and adding evidence to both phrasings moves them together.

Mitigations from the index — the claim
  • paraphrase-augmented training
  • canonicalization

Scored by fmi_5_2_v1 over 5 repeats per case · best context here was General context. Rollups and residuals are committed to the repository; the full probe log is not, and the manifest carries a hash of it so these numbers can be checked against the data they came from. Method.