PersonaTeaming: Exploring How Introducing Personas Can Improve Automated AI Red-Teaming

Fuente: arXiv
Gespeichert in:
Bibliographische Detailangaben
Hauptverfasser: Deng, Wesley Hanwen, Kim, Sunnie S. Y., Jha, Akshita, Holstein, Ken, Eslami, Motahhare, Wilcox, Lauren, Gatys, Leon A
Format: Preprint
Veröffentlicht: 2025
Schlagworte:
Online-Zugang:
Tags: Tag hinzufügen
Keine Tags, Fügen Sie den ersten Tag hinzu!
_version_ 1866912671501123584
author Deng, Wesley Hanwen
Kim, Sunnie S. Y.
Jha, Akshita
Holstein, Ken
Eslami, Motahhare
Wilcox, Lauren
Gatys, Leon A
author_facet Deng, Wesley Hanwen
Kim, Sunnie S. Y.
Jha, Akshita
Holstein, Ken
Eslami, Motahhare
Wilcox, Lauren
Gatys, Leon A
contents Recent developments in AI governance and safety research have called for red-teaming methods that can effectively surface potential risks posed by AI models. Many of these calls have emphasized how the identities and backgrounds of red-teamers can shape their red-teaming strategies, and thus the kinds of risks they are likely to uncover. While automated red-teaming approaches promise to complement human red-teaming by enabling larger-scale exploration of model behavior, current approaches do not consider the role of identity. As an initial step towards incorporating people's background and identities in automated red-teaming, we develop and evaluate a novel method, PersonaTeaming, that introduces personas in the adversarial prompt generation process to explore a wider spectrum of adversarial strategies. In particular, we first introduce a methodology for mutating prompts based on either "red-teaming expert" personas or "regular AI user" personas. We then develop a dynamic persona-generating algorithm that automatically generates various persona types adaptive to different seed prompts. In addition, we develop a set of new metrics to explicitly measure the "mutation distance" to complement existing diversity measurements of adversarial prompts. Our experiments show promising improvements (up to 144.1%) in the attack success rates of adversarial prompts through persona mutation, while maintaining prompt diversity, compared to RainbowPlus, a state-of-the-art automated red-teaming method. We discuss the strengths and limitations of different persona types and mutation methods, shedding light on future opportunities to explore complementarities between automated and human red-teaming approaches.
format Preprint
id arxiv_https___arxiv_org_abs_2509_03728
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle PersonaTeaming: Exploring How Introducing Personas Can Improve Automated AI Red-Teaming
Deng, Wesley Hanwen
Kim, Sunnie S. Y.
Jha, Akshita
Holstein, Ken
Eslami, Motahhare
Wilcox, Lauren
Gatys, Leon A
Artificial Intelligence
Human-Computer Interaction
Recent developments in AI governance and safety research have called for red-teaming methods that can effectively surface potential risks posed by AI models. Many of these calls have emphasized how the identities and backgrounds of red-teamers can shape their red-teaming strategies, and thus the kinds of risks they are likely to uncover. While automated red-teaming approaches promise to complement human red-teaming by enabling larger-scale exploration of model behavior, current approaches do not consider the role of identity. As an initial step towards incorporating people's background and identities in automated red-teaming, we develop and evaluate a novel method, PersonaTeaming, that introduces personas in the adversarial prompt generation process to explore a wider spectrum of adversarial strategies. In particular, we first introduce a methodology for mutating prompts based on either "red-teaming expert" personas or "regular AI user" personas. We then develop a dynamic persona-generating algorithm that automatically generates various persona types adaptive to different seed prompts. In addition, we develop a set of new metrics to explicitly measure the "mutation distance" to complement existing diversity measurements of adversarial prompts. Our experiments show promising improvements (up to 144.1%) in the attack success rates of adversarial prompts through persona mutation, while maintaining prompt diversity, compared to RainbowPlus, a state-of-the-art automated red-teaming method. We discuss the strengths and limitations of different persona types and mutation methods, shedding light on future opportunities to explore complementarities between automated and human red-teaming approaches.
title PersonaTeaming: Exploring How Introducing Personas Can Improve Automated AI Red-Teaming
topic Artificial Intelligence
Human-Computer Interaction
url https://arxiv.org/abs/2509.03728