← Back to article

Equation 4 · How Do We Actually Know a Safety Measure Worked?

What does this equation mean?

pmax⁡≈3k.p_{\max} \approx \frac{3}{k}.

Read the formula alongside the article passage below. Each part has a deeper page with its role in the equation, the supporting passage and nearby citations.

This equation gives an approximation: it relates the quantities while allowing an approximation. Read the equation part by part below; each part has a contextual explanation and a link to its mathematical background.

Read it piece by piece

pmax⁡p_{\max}

Symbol p_max

pmp_max is a part of this expression. Its role is fixed by the surrounding article and by the operations shown in the formula.

Understand this part →

kk

Symbol k

k occurs below the fraction bar. The quantity above the bar is divided by this expression; zero is excluded as a denominator.

Understand this part →

fraction

fraction

Divide the expression above the line by the one below it.

Understand this part →

See an illustrated explanation →
≈

≈

Approximately equal to; the equality is not exact.

Understand this part →

subscript

subscript

The lower label selects a particular version, component, or indexed member of the quantity. For example, x₀ and xₜ can be values at different positions.

Understand this part →

33

Numerator: 3

The complete quantity above the fraction bar.

Understand this part →

How to interpret it

With a fixed numerator, increasing a nonzero denominator reduces the fraction. Its accuracy depends on the assumptions and range of use described in the article.

What the article says around this equation

That bound has a name in elementary statistics, and it is worth stating plainly because it clarifies exactly what a clean red-team result can and cannot license. If k independent attempts are made against a fixed but unknown per-attempt bypass probability p , and all k fail, the standard “rule of three” approximation gives a roughly 95%-confidence upper bound on that probability of pmax⁡≈3kp_{\max} \approx \frac{3}{k}. Applied loosely to a red-team programme, this says a clean record is real evidence, and its strength depends entirely on k — the count of genuinely independent attempts, not the number of hours spent. The Constitutional Classifiers paper reports hours, not a count of independent attempts, so…
Read the full surrounding passage
That bound has a name in elementary statistics, and it is worth stating plainly because it clarifies exactly what a clean red-team result can and cannot license. If k independent attempts are made against a fixed but unknown per-attempt bypass probability p , and all k fail, the standard “rule of three” approximation gives a roughly 95%-confidence upper bound on that probability of pmax⁡≈3kp_{\max} \approx \frac{3}{k}. Applied loosely to a red-team programme, this says a clean record is real evidence, and its strength depends entirely on k — the count of genuinely independent attempts, not the number of hours spent. The Constitutional Classifiers paper reports hours, not a count of independent attempts, so the bound cannot even be computed from the published disclosure as it stands, which is itself informative: hours are a proxy for effort, not a unit that determines a confidence level, and reporting the proxy rather than the underlying count is a gap in what the number can support. The approximation is also optimistic on its own terms, because real red-team attempts are not independent draws — they share technique, tooling, and skill, so successive attempts by the same community are correlated rather than fresh trials, which pulls the true confidence bound weaker than the naive arithmetic suggests.

Read the equation in its article →

Sources cited in the article section

These citations give research context. Read each source to check which claims it supports.

Return to How Do We Actually Know a Safety Measure Worked?

See this formula across 1 published context →

Browse the mathematical compendium →