DREAM: Dynamic Red-teaming across Environments for AI Models

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Lu, Liming, Gu, Xiang, Huang, Junyu, Du, Jiawei, Zheng, Xu, Liu, Yunhuai, Zhou, Yongbin, Pang, Shuchao
Format: Preprint
Published: 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866910008220844032
author Lu, Liming
Gu, Xiang
Huang, Junyu
Du, Jiawei
Zheng, Xu
Liu, Yunhuai
Zhou, Yongbin
Pang, Shuchao
author_facet Lu, Liming
Gu, Xiang
Huang, Junyu
Du, Jiawei
Zheng, Xu
Liu, Yunhuai
Zhou, Yongbin
Pang, Shuchao
contents Large Language Models (LLMs) are increasingly used in agentic systems, where their interactions with diverse tools and environments create complex, multi-stage safety challenges. However, existing benchmarks mostly rely on static, single-turn assessments that miss vulnerabilities from adaptive, long-chain attacks. To fill this gap, we introduce DREAM, a framework for systematic evaluation of LLM agents against dynamic, multi-stage attacks. At its core, DREAM uses a Cross-Environment Adversarial Knowledge Graph (CE-AKG) to maintain stateful, cross-domain understanding of vulnerabilities. This graph guides a Contextualized Guided Policy Search (C-GPS) algorithm that dynamically constructs attack chains from a knowledge base of 1,986 atomic actions across 349 distinct digital environments. Our evaluation of 12 leading LLM agents reveals a critical vulnerability: these attack chains succeed in over 70% of cases for most models, showing the power of stateful, cross-environment exploits. Through analysis of these failures, we identify two key weaknesses in current agents: contextual fragility, where safety behaviors fail to transfer across environments, and an inability to track long-term malicious intent. Our findings also show that traditional safety measures, such as initial defense prompts, are largely ineffective against attacks that build context over multiple interactions. To advance agent safety research, we release DREAM as a tool for evaluating vulnerabilities and developing more robust defenses.
format Preprint
id arxiv_https___arxiv_org_abs_2512_19016
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle DREAM: Dynamic Red-teaming across Environments for AI Models
Lu, Liming
Gu, Xiang
Huang, Junyu
Du, Jiawei
Zheng, Xu
Liu, Yunhuai
Zhou, Yongbin
Pang, Shuchao
Cryptography and Security
Large Language Models (LLMs) are increasingly used in agentic systems, where their interactions with diverse tools and environments create complex, multi-stage safety challenges. However, existing benchmarks mostly rely on static, single-turn assessments that miss vulnerabilities from adaptive, long-chain attacks. To fill this gap, we introduce DREAM, a framework for systematic evaluation of LLM agents against dynamic, multi-stage attacks. At its core, DREAM uses a Cross-Environment Adversarial Knowledge Graph (CE-AKG) to maintain stateful, cross-domain understanding of vulnerabilities. This graph guides a Contextualized Guided Policy Search (C-GPS) algorithm that dynamically constructs attack chains from a knowledge base of 1,986 atomic actions across 349 distinct digital environments. Our evaluation of 12 leading LLM agents reveals a critical vulnerability: these attack chains succeed in over 70% of cases for most models, showing the power of stateful, cross-environment exploits. Through analysis of these failures, we identify two key weaknesses in current agents: contextual fragility, where safety behaviors fail to transfer across environments, and an inability to track long-term malicious intent. Our findings also show that traditional safety measures, such as initial defense prompts, are largely ineffective against attacks that build context over multiple interactions. To advance agent safety research, we release DREAM as a tool for evaluating vulnerabilities and developing more robust defenses.
title DREAM: Dynamic Red-teaming across Environments for AI Models
topic Cryptography and Security
url https://arxiv.org/abs/2512.19016