Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
TRACE — Agentic jailbreak framework for LLM-based agents using scheme-based task decomposition, multi-turn disguising strategies, and adaptive self-evolution to probe emerging security risks. | Kitploit
Tools/GitHubGitHub/zju-llm-safety/trace
ExploitationScripting & AutomationPenetration TestingMachine LearningPapers & ResearchRed TeamingAI SecurityAdversarial Attack
GitHubzju-llm-safety/trace

TRACE

Agentic jailbreak framework for LLM-based agents using scheme-based task decomposition, multi-turn disguising strategies, and adaptive self-evolution to probe emerging security risks.

View Repository
2921817h 19m agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

TRACE: Task-Aware Adaptive Self-Evolving Agentic Jailbreaking

Overview

  • Scheme-based task decomposition. To reduce attack difficulty, we develop around 20 procedural decomposition schemes to resolve a complex harmful task into relatively benign and simple subtask sequences. We measure these candidate sequences through two dimensions, i.e., harmfulness and difficulty, and select the optimal one for instantiating the attack.

  • Execution-oriented multi-turn interaction. For the subtasks that trigger execution refusals, TRACE constructs subtask profiles and retrieves appropriate execution-oriented multi-turn interaction strategies from a continuously evolving strategy library. TRACE leverages the selected strategy to instantiate the subtask and gradually constructs a plausible execution context through multi-turn interactions, inducing the target agent to complete the subtask.

  • Adaptive recovery and strategy evolution. When an intermediate step fails, TRACE localizes the failed subtask, preserves prior progress, adapts the corresponding strategy, and resumes from the failed subtask without starting over. Furthermore, TRACE leverages execution feedback to continuously evolve the execution-oriented strategy library.

Demos

Two recorded demonstrations with Claude Code and Codex are provided in assets/:

Target agentDemo
Claude CodeClaude Code demo
CodexCodex demo

Repository Structure

PathContents
improved_decomposer/Procedural schemes, candidate generation, validation, and selection
experiment/main.pyExperiment orchestration and execution feedback
experiment/runtime/Runtime components for models, strategies, and subtask sequences
experiment/strategy_library/Strategy storage, retrieval, revision, and feedback integration
experiment/config/Experiment configurations and prompt templates
agent_execution/Target-agent interfaces, session handling, trajectory collection, and verification
tools/Benchmark bridges, API adapters, and diagnostics
assets/Claude Code and Codex demonstration videos
environment.ymlConda environment specification

Environment Setup

The provided environment specification targets Linux and Python 3.11.

conda env create -f environment.yml
conda activate trace

Getting Started

1. Configure API Access

Set the credentials and base URL for an OpenAI-compatible Chat Completions endpoint:

export OPENAI_API_KEY="<your-api-key>"
export OPENAI_BASE_URL="<your-api-base-url>"

2. Task Decomposition

python improved_decomposer/improved_task_decomposer.py \
  --data_file_path /path/to/tasks.json \
  --output_file_path outputs/decompositions.jsonl \
  --model "<decomposition-model>" \
  --num_decompositions_per_task 5 \
  --use_schema_decompose

--use_schema_decompose enables scheme-based candidate generation.

3. Run Experiments

The following example uses the AdvCUA benchmark with Codex.

python experiment/main.py \
  --dataset /path/to/benchmark_with_subtasks.jsonl \
  --config experiment/config/config.yaml \
  --lab-backend vrap \
  --compose-file /path/to/benchmark/docker-compose.yml \
  --attacker-model-path /path/to/attacker-model \
  --target-backend codex \
  --codex-model "<target-model>" \
  --responses-base-url "<target-responses-api-base-url>" \
  --responses-env-key OPENAI_API_KEY \
  --strategy-library outputs/experiment/strategy_library.json \
  --output outputs/experiment/results.jsonl

To inspect the available command-line options:

python improved_decomposer/improved_task_decomposer.py --help
python experiment/main.py --help
Download Tool