用自进化框架动态检测大模型安全漏洞,比传统方法更严苛
AgenticEval: Toward Agentic and Self-Evolving Safety Evaluation of Large Language Models
- 构建多智能体系统自动解析政策文档生成测评用例
- 迭代测试中模型安全率从72.50%降至36.36%
- 适合关注AI安全评估的开发者与监管机构
大语言模型在高风险领域快速应用,亟需可靠的安全部署评估。现有静态基准难以应对动态的AI风险和不断变化的法规,形成显著安全缺口。本文提出一种新型代理式安全评估范式,将评估视为持续自我演进的过程而非一次性审计。我们设计了AgenticEval多智能体框架,能自主获取非结构化政策文件,生成并持续演化全面的安全基准。该框架采用专业化智能体协同管道,并引入自进化评估循环,根据评估结果不断优化测试用例。实验表明,随着评估强度提升,模型安全性持续下降:例如,GPT-5在欧盟人工智能法案下的安全率从72.50%降至36.36%。结果揭示了静态评估的局限性,凸显本框架可发现传统方法遗漏的深层漏洞,强调建立动态评估生态系统的紧迫性,以保障先进AI的安全可靠部署。
原文摘要 · Abstract (English)
The rapid integration of Large Language Models (LLMs) into high-stakes domains necessitates reliable safety and compliance evaluation. However, existing static benchmarks are ill-equipped to address the dynamic nature of AI risks and evolving regulations, creating a critical safety gap. This paper introduces a new paradigm of agentic safety evaluation, reframing evaluation as a continuous and self-evolving process rather than a one-time audit. We then propose a novel multi-agent framework AgenticEval, which autonomously ingests unstructured policy documents to generate and perpetually evolve a comprehensive safety benchmark. AgenticEval leverages a synergistic pipeline of specialized agents and incorporates a Self-evolving Evaluation loop, where the system learns from evaluation results to craft progressively more sophisticated and targeted test cases. Our experiments demonstrate the effectiveness of AgenticEval, showing a consistent decline in model safety as the evaluation hardens. For instance, GPT-5's safety rate on the EU AI Act drops from 72.50% to 36.36% over successive iterations. These findings reveal the limitations of static assessments and highlight our framework's ability to uncover deep vulnerabilities missed by traditional methods, underscoring the urgent need for dynamic evaluation ecosystems to ensure the safe and responsible deployment of advanced AI.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。