Stress-testing medical large language models reveals latent safety pathology beyond benchmark accuracy
Summary
This paper introduces AI-MASLD, a stress-audit framework for medical LLMs that reveals how benchmark accuracy can hide serious safety failures, and demonstrates that open-weight models can match or exceed proprietary ones on safety dimensions.
View Cached Full Text
Cached at: 06/09/26, 08:53 AM
# Stress-testing medical large language models reveals latent safety pathology beyond benchmark accuracy Source: [https://arxiv.org/abs/2606.07929](https://arxiv.org/abs/2606.07929) [View PDF](https://arxiv.org/pdf/2606.07929) > Abstract:Large language models \(LLMs\) are entering clinical practice based on benchmark accuracy that may fail to detect safety\-relevant failure modes\. Here we present AI\-MASLD, a stress\-audit framework that adapts the logic of metabolic stress testing from hepatology to the evaluation of clinical LLMs\. Using 240 clinical cases across six narrative perturbation probes, we subjected seven models to double\-stress testing and quantified performance through three indices: metabolic index \(MI\), perturbation flip rate \(PFR\), and counterfactual fairness index \(CFI\)\. Under clean baseline conditions, all models performed uniformly well\. Under realistic narrative stress, performance diverged sharply, revealing two distinct stress\-response phenotypes\. Quantized models exhibited pseudonormalization, in which low flip rates hid functional collapse\. Medical supervised fine\-tuning systematically degraded logical stability, fairness, and information extraction\. An open\-weight model matched or exceeded proprietary alternatives on every safety dimension\. These findings establish narrative stress auditing as a necessary complement to accuracy\-based evaluation\. ## Submission history From: Linghua Yu Prof\. \[[view email](https://arxiv.org/show-email/331fe2cc/2606.07929)\] **\[v1\]**Sat, 6 Jun 2026 01:39:14 UTC \(3,384 KB\)
Similar Articles
A Multi-Domain Red Teaming Framework for Safety, Robustness, and Fairness Evaluation of Medical Large Language Models
This paper presents a multi-domain red teaming framework for evaluating safety, robustness, and fairness of medical LLMs across 690 clinically grounded scenarios. Results show that high aggregate accuracy can mask critical failures, and hybrid evaluation with clinician oversight is necessary for credible safety assessment.
Do No Harm? Hallucination and Actor-Level Abuse in Web-Deployed Medical Large Language Models
This paper presents a large-scale assessment of medical LLMs, including custom MedGPTs and open-source models, finding 25-30% exhibit low factual accuracy and 33.6-54.3% violate operational thresholds, highlighting systemic safety risks.
Benchmarking Large Language Models on Multi-Sensor Physical Hazard Assessment
The paper benchmarks five large language models on multi-sensor physical hazard assessment, revealing that all tested models fail to produce precautionary warnings when multiple sensors are simultaneously elevated below their individual safety limits, while achieving near-perfect accuracy on single-sensor violations.
Ask Before You Diagnose: Safe-Psych, a Sequential Evaluation Benchmark for LLMs in Psychiatry
Introduces Safe-Psych, a sequential benchmark for evaluating how large language models handle diagnostic uncertainty in psychiatry, revealing that even strong models often fail to abstain or seek clarification when clinical evidence is incomplete.
Evaluating medical AI under missing information: same-provider judges and human raters change apparent safety
This paper extends missing-information stress-testing to open-ended medical conversation, finding that LLM judge choice materially changes apparent safety and that LLM judges are more permissive than clinicians.