{"id":"https://openalex.org/W4391632220","doi":"https://doi.org/10.48550/arxiv.2402.04249","title":"HarmBench: A Standardized Evaluation Framework for Automated Red Teaming and Robust Refusal","display_name":"HarmBench: A Standardized Evaluation Framework for Automated Red Teaming and Robust Refusal","publication_year":2024,"publication_date":"2024-02-06","ids":{"openalex":"https://openalex.org/W4391632220","doi":"https://doi.org/10.48550/arxiv.2402.04249"},"language":"en","primary_location":{"id":"pmh:oai:arXiv.org:2402.04249","is_oa":true,"landing_page_url":"http://arxiv.org/abs/2402.04249","pdf_url":"https://arxiv.org/pdf/2402.04249","source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":"","raw_type":null},"type":"preprint","indexed_in":["arxiv","datacite"],"open_access":{"is_oa":true,"oa_status":"green","oa_url":"https://arxiv.org/pdf/2402.04249","any_repository_has_fulltext":true},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5058254793","display_name":"Mantas Mazeika","orcid":null},"institutions":[],"countries":[],"is_corresponding":true,"raw_author_name":"Mazeika, Mantas","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5002959656","display_name":"Long Phan","orcid":"https://orcid.org/0009-0009-4322-6193"},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Phan, Long","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5110849521","display_name":"Xuwang Yin","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Yin, Xuwang","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5004880532","display_name":"Andy Zou","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Zou, Andy","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5032942801","display_name":"Zifan Wang","orcid":"https://orcid.org/0000-0003-3394-8060"},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Wang, Zifan","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5008441432","display_name":"Norman Mu","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Mu, Norman","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5004513620","display_name":"Elham Sakhaee","orcid":"https://orcid.org/0000-0003-0502-3634"},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Sakhaee, Elham","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5026554940","display_name":"Nathaniel Li","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Li, Nathaniel","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5058647826","display_name":"Steven Basart","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Basart, Steven","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5100656393","display_name":"Bo Li","orcid":"https://orcid.org/0000-0001-8849-6183"},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Li, Bo","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5010851725","display_name":"David Forsyth","orcid":"https://orcid.org/0000-0002-2278-0752"},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Forsyth, David","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]},{"author_position":"last","author":{"id":"https://openalex.org/A5020400986","display_name":"Dan Hendrycks","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Hendrycks, Dan","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]}],"institutions":[],"countries_distinct_count":0,"institutions_distinct_count":12,"corresponding_author_ids":["https://openalex.org/A5058254793"],"corresponding_institution_ids":[],"apc_list":null,"apc_paid":null,"fwci":null,"has_fulltext":true,"cited_by_count":20,"citation_normalized_percentile":null,"cited_by_percentile_year":null,"biblio":{"volume":null,"issue":null,"first_page":null,"last_page":null},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11810","display_name":"Complex Systems and Decision Making","score":0.9164999723434448,"subfield":{"id":"https://openalex.org/subfields/1803","display_name":"Management Science and Operations Research"},"field":{"id":"https://openalex.org/fields/18","display_name":"Decision Sciences"},"domain":{"id":"https://openalex.org/domains/2","display_name":"Social Sciences"}},"topics":[{"id":"https://openalex.org/T11810","display_name":"Complex Systems and Decision Making","score":0.9164999723434448,"subfield":{"id":"https://openalex.org/subfields/1803","display_name":"Management Science and Operations Research"},"field":{"id":"https://openalex.org/fields/18","display_name":"Decision Sciences"},"domain":{"id":"https://openalex.org/domains/2","display_name":"Social Sciences"}},{"id":"https://openalex.org/T10734","display_name":"Information and Cyber Security","score":0.9138000011444092,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.3907255530357361}],"concepts":[{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.3907255530357361}],"mesh":[],"locations_count":2,"locations":[{"id":"pmh:oai:arXiv.org:2402.04249","is_oa":true,"landing_page_url":"http://arxiv.org/abs/2402.04249","pdf_url":"https://arxiv.org/pdf/2402.04249","source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":"","raw_type":null},{"id":"doi:10.48550/arxiv.2402.04249","is_oa":true,"landing_page_url":"https://doi.org/10.48550/arxiv.2402.04249","pdf_url":null,"source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":null,"is_accepted":false,"is_published":null,"raw_source_name":null,"raw_type":"article"}],"best_oa_location":{"id":"pmh:oai:arXiv.org:2402.04249","is_oa":true,"landing_page_url":"http://arxiv.org/abs/2402.04249","pdf_url":"https://arxiv.org/pdf/2402.04249","source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":"","raw_type":null},"sustainable_development_goals":[],"awards":[],"funders":[],"has_content":{"pdf":false,"grobid_xml":false},"content_urls":null,"referenced_works_count":0,"referenced_works":[],"related_works":["https://openalex.org/W2748952813","https://openalex.org/W2390279801","https://openalex.org/W2358668433","https://openalex.org/W2376932109","https://openalex.org/W2001405890","https://openalex.org/W2382290278","https://openalex.org/W2478288626","https://openalex.org/W2350741829","https://openalex.org/W2530322880","https://openalex.org/W1596801655"],"abstract_inverted_index":{"Automated":[0],"red":[1,48,59,79],"teaming":[2,60,80],"holds":[3],"substantial":[4],"promise":[5],"for":[6,46,57],"uncovering":[7],"and":[8,62,82,86,118],"mitigating":[9],"the":[10,14,23],"risks":[11],"associated":[12],"with":[13],"malicious":[15],"use":[16],"of":[17,77,109,116],"large":[18],"language":[19],"models":[20],"(LLMs),":[21],"yet":[22],"field":[24],"lacks":[25],"a":[26,42,74,94,106],"standardized":[27,43],"evaluation":[28,44],"framework":[29,45],"to":[30,66],"rigorously":[31],"assess":[32],"new":[33],"methods.":[34],"To":[35],"address":[36],"this":[37],"issue,":[38],"we":[39,72],"introduce":[40,93],"HarmBench,":[41,71],"automated":[47],"teaming.":[49],"We":[50,91,120],"identify":[51],"several":[52],"desirable":[53],"properties":[54],"previously":[55],"unaccounted":[56],"in":[58],"evaluations":[61],"systematically":[63],"design":[64],"HarmBench":[65,113,123],"meet":[67],"these":[68],"criteria.":[69],"Using":[70],"conduct":[73],"large-scale":[75],"comparison":[76],"18":[78],"methods":[81],"33":[83],"target":[84],"LLMs":[85],"defenses,":[87],"yielding":[88],"novel":[89],"insights.":[90],"also":[92],"highly":[95],"efficient":[96],"adversarial":[97],"training":[98],"method":[99],"that":[100],"greatly":[101],"enhances":[102],"LLM":[103],"robustness":[104],"across":[105],"wide":[107],"range":[108],"attacks,":[110],"demonstrating":[111],"how":[112],"enables":[114],"codevelopment":[115],"attacks":[117],"defenses.":[119],"open":[121],"source":[122],"at":[124],"https://github.com/centerforaisafety/HarmBench.":[125]},"counts_by_year":[{"year":2025,"cited_by_count":16},{"year":2024,"cited_by_count":4}],"updated_date":"2026-05-05T08:41:31.759640","created_date":"2025-10-10T00:00:00"}
