arXiv:2512.00412cs.CRcs.AI2025-12ACL

评测大模型推理过程的安全与可靠性,发现其比普通大模型更脆弱。

Red Teaming Large Reasoning Models

  • 构建统一评测基准,从可信度、安全性和效率三方面评估推理模型
  • 26个模型实验显示,推理模型在逻辑攻击下普遍表现不佳
  • 开源工具包,助力后续可信推理研究

大型推理模型(LRMs)在多步推理任务中展现出强大能力,通过显式的思维链(CoT)提升透明度与逻辑一致性。然而,这类模型引入了新型安全与可靠性风险,如思维链劫持和提示诱导的低效问题,现有评估方法未能充分覆盖。为此,我们提出RT-LRM,一个统一的基准,用于评估LRMs的可信度,涵盖真实性、安全性和效率三个核心维度。通过从观察角度设计30个精心筛选的推理任务,对26个模型进行广泛实验,我们发现LRMs普遍面临可信度挑战,且在遭遇推理诱导风险时比大型语言模型(LLMs)更脆弱。这些发现揭示了此前未被充分探索的漏洞,凸显了更针对性评估的必要性。此外,我们发布了可扩展的工具箱,支持标准化可信研究,代码与数据集将开源。

原文摘要 · Abstract (English)

Large Reasoning Models (LRMs) have emerged as a powerful advancement in multi-step reasoning tasks, offering enhanced transparency and logical consistency through explicit chains of thought (CoT). However, these models introduce novel safety and reliability risks, such as CoT-hijacking and prompt-induced inefficiencies, which are not fully captured by existing evaluation methods. To address this gap, we propose RT-LRM, a unified benchmark designed to assess the trustworthiness of LRMs. RT-LRM evaluates three core dimensions: truthfulness, safety and efficiency. Beyond metric-based evaluation, we further introduce the training paradigm as a key analytical perspective to investigate the systematic impact of different training strategies on model trustworthiness. We achieve this by designing a curated suite of 30 reasoning tasks from an observational standpoint. We conduct extensive experiments on 26 models and identify several valuable insights into the trustworthiness of LRMs. For example, LRMs generally face trustworthiness challenges and tend to be more fragile than Large Language Models (LLMs) when encountering reasoning-induced risks. These findings uncover previously underexplored vulnerabilities and highlight the need for more targeted evaluations. In addition, we release a scalable toolbox for standardized trustworthiness research to support future advancements in this important field. Our code and datasets will be open-sourced.

推理模型可信评估安全评测

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。