Identifying the Risks of LM Agents with an LM-Emulated Sandbox

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Ruan, Yangjun, Dong, Honghua, Wang, Andrew, Pitis, Silviu, Zhou, Yongchao, Ba, Jimmy, Dubois, Yann, Maddison, Chris J., Hashimoto, Tatsunori
Format: Preprint
Published: 2023
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866913354110468096
author Ruan, Yangjun
Dong, Honghua
Wang, Andrew
Pitis, Silviu
Zhou, Yongchao
Ba, Jimmy
Dubois, Yann
Maddison, Chris J.
Hashimoto, Tatsunori
author_facet Ruan, Yangjun
Dong, Honghua
Wang, Andrew
Pitis, Silviu
Zhou, Yongchao
Ba, Jimmy
Dubois, Yann
Maddison, Chris J.
Hashimoto, Tatsunori
contents Recent advances in Language Model (LM) agents and tool use, exemplified by applications like ChatGPT Plugins, enable a rich set of capabilities but also amplify potential risks - such as leaking private data or causing financial losses. Identifying these risks is labor-intensive, necessitating implementing the tools, setting up the environment for each test scenario manually, and finding risky cases. As tools and agents become more complex, the high cost of testing these agents will make it increasingly difficult to find high-stakes, long-tailed risks. To address these challenges, we introduce ToolEmu: a framework that uses an LM to emulate tool execution and enables the testing of LM agents against a diverse range of tools and scenarios, without manual instantiation. Alongside the emulator, we develop an LM-based automatic safety evaluator that examines agent failures and quantifies associated risks. We test both the tool emulator and evaluator through human evaluation and find that 68.8% of failures identified with ToolEmu would be valid real-world agent failures. Using our curated initial benchmark consisting of 36 high-stakes tools and 144 test cases, we provide a quantitative risk analysis of current LM agents and identify numerous failures with potentially severe outcomes. Notably, even the safest LM agent exhibits such failures 23.9% of the time according to our evaluator, underscoring the need to develop safer LM agents for real-world deployment.
format Preprint
id arxiv_https___arxiv_org_abs_2309_15817
institution arXiv
publishDate 2023
record_format arxiv
spellingShingle Identifying the Risks of LM Agents with an LM-Emulated Sandbox
Ruan, Yangjun
Dong, Honghua
Wang, Andrew
Pitis, Silviu
Zhou, Yongchao
Ba, Jimmy
Dubois, Yann
Maddison, Chris J.
Hashimoto, Tatsunori
Artificial Intelligence
Computation and Language
Machine Learning
Recent advances in Language Model (LM) agents and tool use, exemplified by applications like ChatGPT Plugins, enable a rich set of capabilities but also amplify potential risks - such as leaking private data or causing financial losses. Identifying these risks is labor-intensive, necessitating implementing the tools, setting up the environment for each test scenario manually, and finding risky cases. As tools and agents become more complex, the high cost of testing these agents will make it increasingly difficult to find high-stakes, long-tailed risks. To address these challenges, we introduce ToolEmu: a framework that uses an LM to emulate tool execution and enables the testing of LM agents against a diverse range of tools and scenarios, without manual instantiation. Alongside the emulator, we develop an LM-based automatic safety evaluator that examines agent failures and quantifies associated risks. We test both the tool emulator and evaluator through human evaluation and find that 68.8% of failures identified with ToolEmu would be valid real-world agent failures. Using our curated initial benchmark consisting of 36 high-stakes tools and 144 test cases, we provide a quantitative risk analysis of current LM agents and identify numerous failures with potentially severe outcomes. Notably, even the safest LM agent exhibits such failures 23.9% of the time according to our evaluator, underscoring the need to develop safer LM agents for real-world deployment.
title Identifying the Risks of LM Agents with an LM-Emulated Sandbox
topic Artificial Intelligence
Computation and Language
Machine Learning
url https://arxiv.org/abs/2309.15817