Equation 8 · How Benchmark Contamination Actually Works in Agentic Evaluation
What does this equation mean?
Read the formula alongside the article passage below. Each part has a deeper page with its role in the equation, the supporting passage and nearby citations.
This equation states an equality: the expressions on both sides have the same value under the article’s assumptions. Read the equation part by part below; each part has a contextual explanation and a link to its mathematical background.
Read it piece by piece
Symbol k
k appears in the bound of this product. The bound states where the repeated operation starts, ends, or which values it includes.
Symbol t
t is an argument of the function-like quantity on the left; its role is set by that function’s stated inputs.
Symbol i
i appears in the bound of this product. The bound states where the repeated operation starts, ends, or which values it includes.
=
The expressions on both sides represent the same quantity under the stated assumptions.
See an illustrated explanation →subscript
The lower label selects a particular version, component, or indexed member of the quantity. For example, x₀ and xₜ can be values at different positions.
superscript
A raised number can be a power. When it is a label or bound, it selects a case or the upper limit of a sum; the formula’s structure distinguishes these uses.
See an illustrated explanation →Starting index or lower bound: i=1
This label says where the repeated addition, multiplication, or accumulation starts. Read its value or condition together with the article’s description of the index.
Ending index or upper bound: k
This label says where the repeated addition, multiplication, or accumulation stops. It sets the last term or end of the range.
How to interpret it
Read it with the definitions, units, and assumptions supplied by the article.
What the article says around this equation
tau-bench itself — the benchmark in which that first exploit was found — was built to move past shallow grading, simulating a multi-turn conversation between a user (played by a language model) and a tool-using agent, then scoring the conversation against the resulting database state, with a pas metric meant to capture reliability across repeated trials rather than a single lucky success [ 7 ] . The mechanism is worth stating precisely, because it is a real assumption pas makes, and the empty-response exploit breaks exactly it: . averaged over tasks to produce the benchmark’s headline number. The metric is designed to punish an agent whose competence is real but…
Read the full surrounding passage
tau-bench itself — the benchmark in which that first exploit was found — was built to move past shallow grading, simulating a multi-turn conversation between a user (played by a language model) and a tool-using agent, then scoring the conversation against the resulting database state, with a pas metric meant to capture reliability across repeated trials rather than a single lucky success [ 7 ] . The mechanism is worth stating precisely, because it is a real assumption pas makes, and the empty-response exploit breaks exactly it: . averaged over tasks to produce the benchmark’s headline number. The metric is designed to punish an agent whose competence is real but inconsistent across resampled trials — a stochastic policy with true per-trial success probability p has , which falls quickly as k grows. But a policy whose output on a given task is deterministic — an empty response, always, regardless of sampling — produces the identical transcript on every trial, so
Sources cited in the surrounding passage
These citations give research context. Read each source to check which claims it supports.
Return to How Benchmark Contamination Actually Works in Agentic Evaluation