paper-with-me

Papers

Deep Research Brings Deeper Harm

2025-10-13 · Shuo Chen, Zonggen Li, Zhen Han, Bailan He, Tong Liu, Haokun Chen, Georg Groh, Philip Torr, Volker Tresp, Jindong Gu arxiv

Deep Research (DR) agents built on Large Language Models (LLMs) can perform complex, multi-step research by decomposing tasks, retrieving online information, and synthesizing detailed reports. However, the misuse of LLMs with such powerful capabilities can lead to even greater risks. This is especially concerning in high-stakes and knowledge-intensive domains such as biosecurity, where DR can generate a professional report containing detailed forbidden knowledge. Unfortunately, we have found such risks in practice: simply submitting a harmful query, which a standalone LLM directly rejects, can elicit a detailed and dangerous report from DR agents. This highlights the elevated risks and underscores the need for a deeper safety analysis. Yet, jailbreak methods designed for LLMs fall short in exposing such unique risks, as they do not target the research ability of DR agents. To address this gap, we propose two novel jailbreak strategies: Plan Injection, which injects malicious sub-goals into the agent's plan; and Intent Hijack, which reframes harmful queries as academic research questions. We conducted extensive experiments across different LLMs and various safety benchmarks, including general and biosecurity forbidden prompts. These experiments reveal 3 key findings: (1) Alignment of the LLMs often fail in DR agents, where harmful prompts framed in academic terms can hijack agent intent; (2) Multi-step planning and execution weaken the alignment, revealing systemic vulnerabilities that prompt-level safeguards cannot address; (3) DR agents not only bypass refusals but also produce more coherent, professional, and dangerous content, compared with standalone LLMs. These results demonstrate a fundamental misalignment in DR agents and call for better alignment techniques tailored to DR agents. Code and datasets are available at https://chenxshuo.github.io/deeper-harm.

📄 PDF Abstract BibTeX arXiv:2510.11851

Code (0)

등록된 구현이 없습니다.

Similar Papers 제목 키워드 기반

A Novel Design of Adaptive and Hierarchical Convolutional Neural Networks using Partial Reconfiguration on FPGA

2019-09-05 · Mohammad Farhadi, Mehdi Ghasemi, Yezhou Yang

Nowadays most research in visual recognition using Convolutional Neural Networks (CNNs) follows the "deeper model with deeper confidence" belief to gain a higher recognition accuracy. At the same time, deeper model bring…

CPUDecision Making

Towards Feature Overcorrelation in Deeper Graph Neural Networks

2021-09-29 · Wei Jin, Xiaorui Liu, Yao Ma, Charu Aggarwal 외

Graph neural networks (GNNs) have achieved great success in graph representation learning, which has tremendously facilitated various real-world applications. Nevertheless, the performance of GNNs significantly deteriora…

Feature CorrelationGraph Representation LearningRepresentation Learning

Towards Unified AI Drug Discovery with Multiple Knowledge Modalities

2023-04-17 · Yizhen Luo, Xing Yi Liu, Kai Yang, Kui Huang 외

In recent years, AI models that mine intrinsic patterns from molecular structures and protein sequences have shown promise in accelerating drug discovery. However, these methods partly lag behind real-world pharmaceutica…

Drug DiscoveryKnowledge GraphsMultimodal Deep LearningProperty Prediction

Revealing the Dark Secrets of Masked Image Modeling

2022-05-26 · CVPR 2023 1 · Zhenda Xie, Zigang Geng, Jingcheng Hu, Zheng Zhang 외

Masked image modeling (MIM) as pre-training is shown to be effective for numerous vision downstream tasks, but how and where MIM works remain unclear. In this paper, we compare MIM with the long-dominant supervised pre-t…

Depth EstimationDiversityInductive BiasMonocular Depth Estimation+4

Bad Company---Neighborhoods in Neural Embedding Spaces Considered Harmful

2016-12-01 · COLING 2016 12 · Johannes Hellrich, Udo Hahn

We assess the reliability and accuracy of (neural) word embeddings for both modern and historical English and German. Our research provides deeper insights into the empirically justified choice of optimal training method…

Word Embeddings