SafeEvolve: Harness-Policy Co-Evolution from Agent Experience for Safety Alignment
- ID: 26f85688
- 原文链接: https://arxiv.org/abs/2609.02786
- PDF: https://arxiv.org/pdf/2609.02786v1
- 作者: Qinghua Mao, Wanying Qu, Dadi Guo, Leitao Yuan, Qingyu Liu, Yu Li, Guanxu Chen, Yanwei Fu, Xi Lin, Xia Hu, Dongrui Liu
- 日期: 2026-09-02
- 更新: 2026-09-02
- 分类: agents
- 来源类型: paper
- 标签: agent-safety, harness-engineering, safety-alignment, reinforcement-learning
- 质量评分: 4/5
- 抓取时间: 2026-09-04T04:22:30Z
中文导读
论文指出 LLM Agent 的表现由基座模型与 harness 共同决定,安全风险同时存在于最终回复与多步执行轨迹中,而现有对齐手段只单靠 harness 更新或策略优化其一SafeEvolve 用已完成 on-policy 轨迹中的安全经验驱动 harness-策略协同进化闭环:harness 侧把轨迹级安全证据转成有界组件级可审计可回滚的安全 prompt 与分层技能更新;策略侧两阶段 SFT-RL先用 harness-use SFT 引导策略利用演进的 harness 产物,再用 verifier 分解奖励的 RL 在多步探索中塑造自主安全行为Qwen3.5-4B 在 AgentDojo 上攻击成功率降为 1/3,良性效用从 59.79% 升至 61.86%(cs.AI, cs.CR,2026-09-02)
为什么值得关注
论文指出 LLM Agent 的表现由基座模型与 harness 共同决定,安全风险同时存在于最终回复与多步执行轨迹中... 该工作由 arXiv 摘要直接背书:结论、实验设置与指标均出自摘要原文(2026-09-02 提交,cs.AI, cs.CR),适合关注 agents 方向的近期进展。
关键信息
- 论文标题:SafeEvolve: Harness-Policy Co-Evolution from Agent Experience for Safety Alignment
- 作者:Qinghua Mao, Wanying Qu, Dadi Guo, Leitao Yuan, Qingyu Liu, Yu Li, Guanxu Chen, Yanwei Fu, Xi Lin, Xia Hu, Dongrui Liu
- arXiv:https://arxiv.org/abs/2609.02786
- 发布时间:2026-09-02
- arXiv 分类:cs.AI, cs.CR
- 关联标签:agent-safety, harness-engineering, safety-alignment, reinforcement-learning
- 项目主页:https://github.com/MaoPopovich/SafeEvolve
English Abstract
The performance of LLM-based agents is jointly shaped by the base model and the harness used when interacting with the environment. This exposes them to safety risks in both harmful final responses and multi-step execution trajectories. Existing safety alignment mechanisms often rely on either external harness updates or policy optimization, yet applying either paradigm in isolation fails to bridge runtime control with intrinsic safety. We propose SafeEvolve, an experience-driven self-evolving framework for agent safety alignment. SafeEvolve leverages safety experience from completed on-policy trajectories to drive a continual loop of harness-policy co-evolution. On the harness side, SafeEvolve converts trajectory-level safety evidence into bounded, component-level updates across safety prompt and hierarchical skills, yielding auditable and reversible harness artifacts. On the policy side, SafeEvolve follows a two-stage SFT-RL paradigm, where harness-use SFT bootstraps the policy to actively leverage evolved harness artifacts, and harness-augmented RL further shapes autonomous safety behaviors during multi-step exploration via verifier-decomposed rewards. Through harness-policy co-evolution, SafeEvolve converts safety experience into an evolved runtime harness and improved policy behavior. Experiments on agentic safety benchmarks show that SafeEvolve achieves a stronger safety-utility tradeoff than existing baselines. For Qwen3.5-4B, SafeEvolve achieves a $3\times$ ASR reduction on AgentDojo while improving benign utility from 59.79% to 61.86%.
English Summary
LLM-based agent performance is jointly shaped by the base model and the harness used to interact with the environment, exposing safety risks in both final responses and multi-step execution trajectories. SafeEvolve is an experience-driven self-evolving framework for agent safety alignment: it leverages safety experience from completed on-policy trajectories to drive a continual harness-policy co-evolution loop. On the harness side, trajectory-level safety evidence is converted into bounded, component-level updates across safety prompts and hierarchical skills, yielding auditable and reversible harness artifacts. On the policy side, a two-stage SFT-RL paradigm bootstraps the policy to leverage evolved harness artifacts, then shapes autonomous safety behavior during multi-step exploration via verifier-decomposed rewards....
Obsidian Notes
- 内容由
opencli arxiv paper拉取 arXiv 元数据与摘要生成。 - 中文导读与价值判断均锚定在条目已有摘要、论文摘要、作者、日期与分类信息上;未补充论文摘要之外的实验细节。