SHE: Trajectory-driven Safety Harness Evolution for LLM Agents

2026-08-10Artificial Intelligence

Artificial IntelligenceComputer Vision and Pattern Recognition
AI summary

The authors explain that keeping AI language agents safe isn't just about the AI model itself, but also about the system that controls how the model interacts with its environment, like managing memory and tools. They created a method called Safety Harness Evolution (SHE) that breaks this control system into clear parts, each responsible for safety. SHE learns from mistakes during use, updates these parts to improve safety, and checks to make sure the updates still let the agent work well. Their tests show that SHE makes agents much safer and still useful, and it works even on new kinds of safety issues and different AI models without needing extra changes.

Large Language Model (LLM)Safety HarnessAgent SafetySystem PromptRule BankSafety MemoryTool PolicyTrajectory FailuresSafety-Utility ValidationAgent-SafetyBench
Authors
Wanying Qu, Qinghua Mao, Yu Li, Jiyao Liu, Xin Zhang, Dadi Guo, Yanxu Zhu, Qingyu Liu, Leitao Yuan, Xi Lin, Shanfeng Zhu, Yanwei Fu, Jing Shao, Xia Hu, Dongrui Liu
Abstract
The safety of large language model (LLM) agents depends not only on model weights but also on the agent harness that manages context, memory, tools, permissions, and runtime control. Existing safety mechanisms often treat the harness as a fixed deployment artifact, limiting their ability to evolve with emerging risks. Moreover, coupled functions across harness components obscure safety responsibility attribution, making localized evolution difficult. We propose Safety Harness Evolution (SHE), a framework that learns evolving safe boundaries from rollout trajectories. SHE decomposes the harness into four artifacts with explicit safety responsibilities, including the System Prompt, Rule Bank, Safety Memory, and Tool Policy, defining clear functional boundaries for localized evolution. Based on this decomposition, SHE introduces an attribution-guided evolution loop that converts trajectory failures into structured diagnoses, learns artifact-specific boundary refinements, and selects evolved harnesses through safety-utility validation. Experiments on Agent-SafetyBench demonstrate that SHE effectively enhances safety through harness evolution, achieving a 3.1x ASR reduction compared with static SafeHarness, while also improving benign utility. The evolved harness further generalizes to unseen risks on the held-out AgentHarm benchmark and transfers across agent models without additional evolution.