Share your thoughts, 1 month free Claude Pro on usSee more
WorkDL logo mark

Learning to Attack and Defend: Adaptive Red Teaming of Language Models via GRPO

About

AI red teaming must continually adapt to evolving attackers and defenders. Reinforcement learning offers a promising approach to discovering novel attacks, and co-training methods can produce more robust defenders in tandem. Recent works have demonstrated the efficacy of attacker-defender co-training by applying PPO and DPO, but report that GRPO is unstable in this setting. We introduce AdvGRPO, a co-training framework that makes GRPO viable for joint attacker-defender optimization using dense multi-channel rewards and decoupled advantage normalization. Training progresses through a curriculum from single-turn to closed-loop multi-turn attacks before bootstrapping co-training, where attacker and defender models are updated in alternation. We show that our method can produce highly effective and transferable attacks and that co-trained defenders outperform baselines on safety benchmarks.

Blake Bullwinkel, Eugenia Kim, Amanda Minnich, Mark Russinovich• 2026

Related benchmarks

TaskDatasetResultRank
Safety EvaluationHarmBench
ASR0.9
153
Safety EvaluationWildGuard (test)--
27
Safety EvaluationDAN--
26
Benign ComplianceWJB (WildJailbreak)
Compliance Rate72.8
15
Adversarial AttackHarmBench standard behaviors
ASR91
13
Adversarial AttackAdvBench (held-out split)
ASR90
13
Benign ComplianceXSTest
Comply Score91.6
12
Jailbreak AttackAdvBench (held-out)
ASR69.1
9
Jailbreak AttackHarmBench standard behaviors
ASR61
9
Instruction FollowingIFBench
Utility Score33.3
5
Showing 10 of 13 rows

Other info

Follow for update