SafeEvolve:利用智能体经验进行安全对齐的 harness-策略协同进化
SafeEvolve: Harness-Policy Co-Evolution from Agent Experience for Safety Alignment
浏览论文内容
中文总结 AI 辅助
SafeEvolve是一种基于智能体经验的安全对齐自进化框架,通过harness-策略协同进化实现更优的安全-效用权衡,在Qwen3.5-4B上可降低AgentDojo的ASR并提升良性效用
中文摘要 AI 辅助
基于大语言模型(LLM)的智能体性能由基础模型及其与环境交互时使用的harness共同决定,这使其在有害最终响应和多步执行轨迹两方面均面临安全风险。现有安全对齐机制通常依赖外部harness更新或策略优化,但单独应用任一范式均无法将运行时控制与内在安全相衔接。我们提出SafeEvolve,一种基于经验的智能体安全对齐自进化框架。SafeEvolve利用已完成的on-policy轨迹的安全经验,驱动harness-策略协同进化的持续循环。在harness侧,SafeEvolve将轨迹级安全证据转换为安全提示和分层技能层面的有界组件级更新,生成可审计且可逆的harness产物;在策略侧,SafeEvolve采用两阶段SFT-RL范式,其中使用harness的SFT引导策略主动利用进化后的harness产物,harness增强型RL则通过验证器分解的奖励在多步探索期间进一步塑造自主安全行为。通过harness-策略协同进化,SafeEvolve将安全经验转化为进化后的运行时harness和改进的策略行为。在智能体安全基准测试上的实验表明,SafeEvolve相较于现有基线实现了更优的安全-效用权衡;对于Qwen3.5-4B,SafeEvolve在AgentDojo上将ASR降低3倍,同时将良性效用从59.79%提升至61.86%。
英文摘要
The performance of LLM-based agents is jointly shaped by the base model and the harness used when interacting with the environment. This exposes them to safety risks in both harmful final responses and multi-step execution trajectories. Existing safety alignment mechanisms often rely on either external harness updates or policy optimization, yet applying either paradigm in isolation fails to bridge runtime control with intrinsic safety. We propose SafeEvolve, an experience-driven self-evolving framework for agent safety alignment. SafeEvolve leverages safety experience from completed on-policy trajectories to drive a continual loop of harness-policy co-evolution. On the harness side, SafeEvolve converts trajectory-level safety evidence into bounded, component-level updates across safety prompt and hierarchical skills, yielding auditable and reversible harness artifacts. On the policy side, SafeEvolve follows a two-stage SFT-RL paradigm, where harness-use SFT bootstraps the policy to actively leverage evolved harness artifacts, and harness-augmented RL further shapes autonomous safety behaviors during multi-step exploration via verifier-decomposed rewards. Through harness-policy co-evolution, SafeEvolve converts safety experience into an evolved runtime harness and improved policy behavior. Experiments on agentic safety benchmarks show that SafeEvolve achieves a stronger safety-utility tradeoff than existing baselines. For Qwen3.5-4B, SafeEvolve achieves a $3\times$ ASR reduction on AgentDojo while improving benign utility from 59.79% to 61.86%.
发表机构
- Shanghai AI Laboratory(上海人工智能实验室)
- SJTU(上海交通大学)
- Fudan University(复旦大学)
- HKUST(香港科技大学)
- Zhejiang University(浙江大学)
机构由 AI 辅助整理,请以论文原文为准。