acceptodds
Under review as a conference paper at ICLR 2027

Probing Biosafety Risks in LLMs via Skill-Driven Agentic Jailbreaking

Abstract

Large language models (LLMs) are increasingly used in biological research, raising growing concerns about their potential biosafety risks. However, existing safety evaluations largely rely on static, single-turn queries, which may substantially underestimate risks that emerge through sustained and adaptive interaction. We introduce BioSafeProbe, a skill-driven agentic jailbreaking framework for systematically probing such biosafety risks in LLMs. BioSafeProbe formulates safety testing as a sequential decision process that adaptively explores model safety boundaries over complete interaction trajectories. It decomposes complex risk objectives, dynamically selects and orchestrates reusable interaction skills according to the evolving testing state, evaluates intermediate risk exposure and task progress, and updates subsequent strategies based on model feedback and prior interaction experience. We further construct BioRisk, an open-ended biosafety evaluation dataset comprising 300 risk tasks across 10 categories. Experiments across 10 frontier LLMs show that BioSafeProbe increases the average risk exposure rate from 31.3% to 87.7%, revealing substantially more biosafety risks that would otherwise remain undetected. Fine-grained analyses further show that some risks emerge only after multiple interaction turns and exhibit distinct patterns across risk categories, target models, and interaction trajectories.

open until 14 Dec 2026

est. 32% chance this paper gets accepted at ICLR 2027.

Reject 68%Accept 32%

What do you think this paper will get?

All positions stay anonymous.

Related papers

Loading the map…

Discussion (0)

Sign in to comment.