Tree-based Dialogue Reinforced Policy Optimization for Red-Teaming Attacks

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Guo, Ruohao, Oroojlooy, Afshin, Sridhar, Roshan, Ballesteros, Miguel, Ritter, Alan, Roth, Dan
Format: Preprint
Published: 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866911499206787072
author Guo, Ruohao
Oroojlooy, Afshin
Sridhar, Roshan
Ballesteros, Miguel
Ritter, Alan
Roth, Dan
author_facet Guo, Ruohao
Oroojlooy, Afshin
Sridhar, Roshan
Ballesteros, Miguel
Ritter, Alan
Roth, Dan
contents Despite recent rapid progress in AI safety, current large language models remain vulnerable to adversarial attacks in multi-turn interaction settings, where attackers strategically adapt their prompts across conversation turns and pose a more critical yet realistic challenge. Existing approaches that discover safety vulnerabilities either rely on manual red-teaming with human experts or employ automated methods using pre-defined templates and human-curated attack data, with most focusing on single-turn attacks. However, these methods did not explore the vast space of possible multi-turn attacks, failing to consider novel attack trajectories that emerge from complex dialogue dynamics and strategic conversation planning. This gap is particularly critical given recent findings that LLMs exhibit significantly higher vulnerability to multi-turn attacks compared to single-turn attacks. We propose DialTree, an on-policy reinforcement learning framework integrated with tree search that autonomously discovers diverse multi-turn attack strategies by treating the dialogue as a sequential decision-making problem, enabling systematic exploration without manually curated data. Through extensive experiments, our approach not only achieves more than 44.2% higher ASR across 12 target models compared to previous state-of-the-art approaches, but also effectively uncovers new attack strategies by learning optimal dialogue policies that maximize attack success across multiple turns.
format Preprint
id arxiv_https___arxiv_org_abs_2510_02286
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Tree-based Dialogue Reinforced Policy Optimization for Red-Teaming Attacks
Guo, Ruohao
Oroojlooy, Afshin
Sridhar, Roshan
Ballesteros, Miguel
Ritter, Alan
Roth, Dan
Machine Learning
Artificial Intelligence
Computation and Language
Despite recent rapid progress in AI safety, current large language models remain vulnerable to adversarial attacks in multi-turn interaction settings, where attackers strategically adapt their prompts across conversation turns and pose a more critical yet realistic challenge. Existing approaches that discover safety vulnerabilities either rely on manual red-teaming with human experts or employ automated methods using pre-defined templates and human-curated attack data, with most focusing on single-turn attacks. However, these methods did not explore the vast space of possible multi-turn attacks, failing to consider novel attack trajectories that emerge from complex dialogue dynamics and strategic conversation planning. This gap is particularly critical given recent findings that LLMs exhibit significantly higher vulnerability to multi-turn attacks compared to single-turn attacks. We propose DialTree, an on-policy reinforcement learning framework integrated with tree search that autonomously discovers diverse multi-turn attack strategies by treating the dialogue as a sequential decision-making problem, enabling systematic exploration without manually curated data. Through extensive experiments, our approach not only achieves more than 44.2% higher ASR across 12 target models compared to previous state-of-the-art approaches, but also effectively uncovers new attack strategies by learning optimal dialogue policies that maximize attack success across multiple turns.
title Tree-based Dialogue Reinforced Policy Optimization for Red-Teaming Attacks
topic Machine Learning
Artificial Intelligence
Computation and Language
url https://arxiv.org/abs/2510.02286