自动整合新攻击的红队框架,提升大模型安全测试效率与覆盖度。
AutoRedTeamer: Autonomous Red Teaming with Lifelong Attack Integration
- 多智能体架构自动生成并执行攻击用例,持续学习新威胁。
- 在HarmBench上对Llama-3.1-70B攻击成功率提升20%,成本降低46%。
- 无需人工干预,适合大规模、持续演进的AI系统安全评估。
随着大语言模型(LLMs)能力不断增强,其安全与可靠性评估日益重要。现有红队测试方法仍依赖人工输入,难以覆盖新兴攻击向量。本文提出AutoRedTeamer,一种全自动化端到端的红队测试框架。该框架采用双智能体结构:红队代理基于风险类别生成并执行测试用例;策略提议代理通过分析最新研究自主发现并实施新攻击。模块化设计使系统能动态适应新威胁,同时保持对已有攻击的有效性。在多种评测场景中,AutoRedTeamer在HarmBench上对Llama-3.1-70B的攻击成功率提升20%,计算成本降低46%。生成测试用例的多样性与人工基准相当,提供了一种可扩展、持续演进的AI系统安全评估方案。
原文摘要 · Abstract (English)
As large language models (LLMs) become increasingly capable, security and safety evaluation are crucial. While current red teaming approaches have made strides in assessing LLM vulnerabilities, they often rely heavily on human input and lack comprehensive coverage of emerging attack vectors. This paper introduces AutoRedTeamer, a novel framework for fully automated, end-to-end red teaming against LLMs. AutoRedTeamer combines a multi-agent architecture with a memory-guided attack selection mechanism to enable continuous discovery and integration of new attack vectors. The dual-agent framework consists of a red teaming agent that can operate from high-level risk categories alone to generate and execute test cases and a strategy proposer agent that autonomously discovers and implements new attacks by analyzing recent research. This modular design allows AutoRedTeamer to adapt to emerging threats while maintaining strong performance on existing attack vectors. We demonstrate AutoRedTeamer's effectiveness across diverse evaluation settings, achieving 20% higher attack success rates on HarmBench against Llama-3.1-70B while reducing computational costs by 46% compared to existing approaches. AutoRedTeamer also matches the diversity of human-curated benchmarks in generating test cases, providing a comprehensive, scalable, and continuously evolving framework for evaluating the security of AI systems.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。