RedTopic: Toward Topic-Diverse Red Teaming of Large Language Models

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Ding, Jiale, Zheng, Xiang, Wu, Yutao, Wang, Cong, Lee, Wei-Bin, Pan, Ling, Ma, Xingjun, Jiang, Yu-Gang
Format: Preprint
Published: 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866910066866651136
author Ding, Jiale
Zheng, Xiang
Wu, Yutao
Wang, Cong
Lee, Wei-Bin
Pan, Ling
Ma, Xingjun
Jiang, Yu-Gang
author_facet Ding, Jiale
Zheng, Xiang
Wu, Yutao
Wang, Cong
Lee, Wei-Bin
Pan, Ling
Ma, Xingjun
Jiang, Yu-Gang
contents As large language models (LLMs) are increasingly deployed as black-box components in real-world applications, red teaming has become essential for identifying potential risks. It tests LLMs with adversarial prompts to uncover vulnerabilities and improve safety alignment. Ideally, effective red teaming should be adaptive to evolving LLM capabilities and explore a broad range of harmful topics. However, existing approaches face two limitations: 1) topic-based approaches rely on pre-collected harmful topics, limited in flexibility and adaptivity. 2) topic-free methods use reinforcement learning (RL), but they lack an explicit reward signal for exploration and tend to over-optimize a narrow objective, reducing topic diversity. To address these limitations, we propose RedTopic, a novel red teaming framework that generates topic-diverse adversarial prompts through a contextualized generation pipeline, an aggregate reward design, and a multi-objective RL training loop. Experiments show that RedTopic produces more effective and diverse adversarial prompts than existing methods, with notable improvements in integrated evaluation metrics. We believe RedTopic represents a step toward more adaptive and topic-diverse red teaming for large language models.
format Preprint
id arxiv_https___arxiv_org_abs_2507_00026
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle RedTopic: Toward Topic-Diverse Red Teaming of Large Language Models
Ding, Jiale
Zheng, Xiang
Wu, Yutao
Wang, Cong
Lee, Wei-Bin
Pan, Ling
Ma, Xingjun
Jiang, Yu-Gang
Machine Learning
Artificial Intelligence
Computation and Language
Computers and Society
As large language models (LLMs) are increasingly deployed as black-box components in real-world applications, red teaming has become essential for identifying potential risks. It tests LLMs with adversarial prompts to uncover vulnerabilities and improve safety alignment. Ideally, effective red teaming should be adaptive to evolving LLM capabilities and explore a broad range of harmful topics. However, existing approaches face two limitations: 1) topic-based approaches rely on pre-collected harmful topics, limited in flexibility and adaptivity. 2) topic-free methods use reinforcement learning (RL), but they lack an explicit reward signal for exploration and tend to over-optimize a narrow objective, reducing topic diversity. To address these limitations, we propose RedTopic, a novel red teaming framework that generates topic-diverse adversarial prompts through a contextualized generation pipeline, an aggregate reward design, and a multi-objective RL training loop. Experiments show that RedTopic produces more effective and diverse adversarial prompts than existing methods, with notable improvements in integrated evaluation metrics. We believe RedTopic represents a step toward more adaptive and topic-diverse red teaming for large language models.
title RedTopic: Toward Topic-Diverse Red Teaming of Large Language Models
topic Machine Learning
Artificial Intelligence
Computation and Language
Computers and Society
url https://arxiv.org/abs/2507.00026