Chiron: Agentic Platform for Automated Setting Design and Red-Blue Protocol Optimization in ControlArena
Giovanni Maria Occhipinti · Team Therion Labs
Submitted to AI Control Hackathon 2026. Sprint projects are early-stage work by participants, not Apart Research publications.
As AI systems are deployed across increasingly diverse domains, the long tail of risks grows faster than researchers can manually design evaluation scenarios for them. AI control depends on domain-specific settings and protocols, both of which are expensive to create. ControlArena provides a foundational benchmark for building and stress-testing control protocols faster, but today ships with only 14 hand-crafted settings, each requiring days of expert engineering. Moreover, even once a setting exists, choosing a robust protocol for it remains a painful manual process. We present Chiron, an agentic plugin for ControlArena that automates two core bottlenecks: (1) generating diverse and realistic evaluation settings from natural-language domain and threat descriptions, and (2) designing novel control protocols through iterative red-blue optimization. We evaluate Chiron's setting design pipeline through a blinded LLM-judge comparing 5 synthetic settings against 5 hand-crafted ControlArena settings using a novel rubric of 5 axes, finding that synthetic settings achieve equivalent or better design quality (3.83 vs. 3.41 overall, p < 10⁻⁷). We further demonstrate the agentic red-blue protocol co-evolution on the Bash setting, showing that LLM agents can discover novel attack strategies and adaptively strengthen monitoring protocols through multiple rounds of alternating optimization with Pareto constraints. Together, these contributions may provide a modular framework for scaling AI control research operations.
Reviews
The red-blue co-evolution experiment needs significantly more scale (more rounds, more tasks, multiple settings) to draw meaningful conclusions. Consider prioritizing depth on one setting before breadth.
Congrats on a strong hackathon project! The setting generation pipeline addresses a real bottleneck in AI control research, and the system design is well thought through. The report is clearly written and notably honest about its limitations, which makes it easy to evaluate and build on.
Impact & Innovation: The automated setting generation is the standout contribution. Automating ControlArena setting creation from natural-language domain descriptions addresses a real bottleneck, and could meaningfully accelerate the field's ability to test control protocols across diverse domains.The red-blue co-evolution is an interesting concept but likely too ambitious to pull off in a reduced time. Prior work has explored both monitor iteration (https://www.lesswrong.com/posts/bALBxf3yGGx4bvvem/prompt-optimization-can-enable-ai-control-research) as well as attack adaptation (https://arxiv.org/abs/2510.09462) and automation (https://www.lesswrong.com/posts/X8qTKsGcnsTFrqM96/monitoring-benchmark-for-ai-control), but most remain open problems.
Execution Quality:
- The LLM-judge evaluation of synthetic settings is a reasonable first pass, but they need further exploration and testing. The natural next step would be to actually use the synthetic settings: try attacks, test how existing blue-team protocols fare, and see whether the settings produce meaningful signal. Reaching out to teams working on control evaluations (e.g. UKAISI, Redwood Research) for feedback on the pipeline and outputs would also help calibrate quality beyond what an LLM judge can assess.
- The red-blue co-evolution is a promising direction, but the results are hard to interpret given the small scale. For future projects, consider whether deeper investment in one contribution (e.g. end-to-end validation of the synthetic settings) might produce stronger results than splitting effort across two ambitious pipelines.
Presentation & Clarity: The paper is well-structured, diagrams add value (although some might be redundant), and the narrative flows cleanly from problem to method to results to caveats. The limitations section is specific and raises relevant shortcomings.
Read full reviewShow less
Cite this project
@misc{occhipinti2026chiron,
title = {{Chiron: Agentic Platform for Automated Setting Design and Red-Blue Protocol Optimization in ControlArena}},
author = {Giovanni Maria Occhipinti},
year = {2026},
month = mar,
note = {Submitted to AI Control Hackathon 2026, an Apart Research Sprint},
howpublished = {\url{https://apartresearch.com/sprints/projects/chiron-agentic-platform-for-automated-setting-design-and-redblue-protocol-optimization-in-controlarena-52r0}},
url = {https://apartresearch.com/sprints/projects/chiron-agentic-platform-for-automated-setting-design-and-redblue-protocol-optimization-in-controlarena-52r0}
}More from AI Control Hackathon 2026
- 1st placeLinuxArena track winnerView project: Omission Attacks: When Doing Nothing Is the Attack
Omission Attacks: When Doing Nothing Is the Attack
MAIA
AI control protocols monitor agent actions to detect sabotage, but omission attacks exploit what the agent fails to do rather than what it does. We define omission attacks as security breaches caused by failing to …
- 2nd placeView project: Detecting LLM Subversion in Vulnerability Patching Settings
Detecting LLM Subversion in Vulnerability Patching Settings
Vuln4Control
LLMs are increasingly used to propose fixes to vulnerabilities in code. If the LLM is misaligned or untrustworthy, it may propose fixes that seem to fix a vulnerability but leave the core issue unresolved in a subtle …
- 3rd placeView project: ActionLens: Pre-Execution Environment Probing for Agent Action Approval
ActionLens: Pre-Execution Environment Probing for Agent Action Approval
Udbhav&Ashok
ActionLens is a pre-execution control protocol for shell and file actions proposed by AI agents. Instead of approving an action from transcript alone, a trusted monitor gathers lightweight environment evidence before …