LLM-based agents are increasingly deployed in product-level execution harnesses, where jailbreaks can trigger harmful tool use and persistent state changes, creating greater risks than unsafe text generation alone. Existing automatic red-teaming methods often rely on fixed attacks, while recent agentic attackers coordinate multiple jailbreak tools and show stronger potential through trajectory-based retrieval. However, such retrieval can reuse misleading experiences due to retrieval bias and unclear tool credit, and full trajectories add context overhead while reducing interpretability. We propose RedEvoAgent, a black-box red-teaming agent that distills cross-case attack trajectories into a concise, human-readable attack skill. The attack skill adaptively evolves through tool-effectiveness profiling and Deciding-Tool Attribution for skill updates, and a validation ratchet that retains only updates improving validation performance. Experiments on multiple benchmarks, target models, and target execution harnesses show that RedEvoAgent outperforms fixed and agentic baselines, improves tool efficiency, and transfers across attacker models and target execution harnesses.
Jun-Jie Zhang, Hui Liu, Kecheng Chen et al.· 0 citations
This work proposes a closed-loop Multi-Agent Simulation Framework to synthe-size diverse, faithful, and policy-aligned shopping trajectories, and presents synthetic data that enables a small model to significantly outperform same-size baselines and surpass a large-model baseline.
Qing Ping, Changyou Chen, Binxuan Huang· Proceedings of the 64th Annu...· 0 citations