Skip to content
Sprint projectMar 23, 2026Bologna

Chiron: Agentic Platform for Automated Setting Design and Red-Blue Protocol Optimization in ControlArena

Giovanni Maria Occhipinti · Team Therion Labs

Submitted to AI Control Hackathon 2026. Sprint projects are early-stage work by participants, not Apart Research publications.

Read the report

Report: Chiron: Agentic Platform for Automated Setting Design and Red-Blue Protocol Optimization in ControlArena

Code (opens in new tab)
Share

As AI systems are deployed across increasingly diverse domains, the long tail of risks grows faster than researchers can manually design evaluation scenarios for them. AI control depends on domain-specific settings and protocols, both of which are expensive to create. ControlArena provides a foundational benchmark for building and stress-testing control protocols faster, but today ships with only 14 hand-crafted settings, each requiring days of expert engineering. Moreover, even once a setting exists, choosing a robust protocol for it remains a painful manual process. We present Chiron, an agentic plugin for ControlArena that automates two core bottlenecks: (1) generating diverse and realistic evaluation settings from natural-language domain and threat descriptions, and (2) designing novel control protocols through iterative red-blue optimization. We evaluate Chiron's setting design pipeline through a blinded LLM-judge comparing 5 synthetic settings against 5 hand-crafted ControlArena settings using a novel rubric of 5 axes, finding that synthetic settings achieve equivalent or better design quality (3.83 vs. 3.41 overall, p < 10⁻⁷). We further demonstrate the agentic red-blue protocol co-evolution on the Bash setting, showing that LLM agents can discover novel attack strategies and adaptively strengthen monitoring protocols through multiple rounds of alternating optimization with Pareto constraints. Together, these contributions may provide a modular framework for scaling AI control research operations.

Reviews

Judging this Sprint?

Review this project

Your public critique appears on this page without your name. Your private critique is not published; only the Apart team reads it. If you agree below, we share your review with grantmaking.ai (opens in new tab) and the Transformative AI Fund so strong projects can be funded.

Not shown on this page.

Shown on this page, without your name.

Only the Apart team reads this, and funders if you agree below.

Share my name publicly on grantmaking.ai *
Share my private critique with funders *

How much would this matter for AI safety if it worked? How innovative is it? For scores of 4-5: is this actually new to the field, or replicating recent work?

Scoring guide
  1. 1Negligible. No clear problem addressed, or no meaningful novelty.
  2. 2Limited. Addresses a real problem but with a generic or well-trodden approach. Incremental at best.
  3. 3Moderate. Clear problem with a reasonable approach; some novelty in framing or method beyond routine application of existing tools.
  4. 4Significant. Important problem with an original approach, or identifies a neglected problem area. A valuable contribution others could build on.
  5. 5Exceptional. Tackles a critical AI safety problem with a genuinely novel approach, or opens a new research direction. Clear theory of change. You'd be excited to share this with researchers in the area.

How sound are methodology, implementation, and findings?

Scoring guide
  1. 1Seriously flawed. Methodology broken, results uninterpretable, or implementation doesn't work.
  2. 2Weak. Approach has significant gaps: missing validation, flawed experimental design, or incomplete implementation.
  3. 3Competent. Technically solid given the short duration. Methodology makes sense, results are interpretable, limitations acknowledged, work builds toward clear conclusions.
  4. 4Strong. Thorough methodology with convincing validation. Results clearly support conclusions. Immediately useful for future work.
  5. 5Exceptional. Ambitious scope executed rigorously. Surprising findings, novel methods, or unusually robust validation.

How clearly are work, findings, and impact potential communicated?

Scoring guide
  1. 1Incomprehensible. Cannot determine what the project is actually claiming or doing.
  2. 2Hard to follow. Key information buried, missing, or diluted by excessive length. Significant effort to extract main points.
  3. 3Clear enough. Can understand the problem, approach, and results without undue effort. Core content clearly present: problem, method, findings, limitations.
  4. 4Well presented. Easy to follow, well-structured, appropriate level of detail. Target audience would get it quickly.
  5. 5Exceptionally clear. A pleasure to read. Complex ideas made accessible. Could serve as a model for how to present this type of work.

  1. The red-blue co-evolution experiment needs significantly more scale (more rounds, more tasks, multiple settings) to draw meaningful conclusions. Consider prioritizing depth on one setting before breadth.

  2. Congrats on a strong hackathon project! The setting generation pipeline addresses a real bottleneck in AI control research, and the system design is well thought through. The report is clearly written and notably honest about its limitations, which makes it easy to evaluate and build on.

    Impact & Innovation: The automated setting generation is the standout contribution. Automating ControlArena setting creation from natural-language domain descriptions addresses a real bottleneck, and could meaningfully accelerate the field's ability to test control protocols across diverse domains.The red-blue co-evolution is an interesting concept but likely too ambitious to pull off in a reduced time. Prior work has explored both monitor iteration (https://www.lesswrong.com/posts/bALBxf3yGGx4bvvem/prompt-optimization-can-enable-ai-control-research) as well as attack adaptation (https://arxiv.org/abs/2510.09462) and automation (https://www.lesswrong.com/posts/X8qTKsGcnsTFrqM96/monitoring-benchmark-for-ai-control), but most remain open problems.

    Execution Quality:

    - The LLM-judge evaluation of synthetic settings is a reasonable first pass, but they need further exploration and testing. The natural next step would be to actually use the synthetic settings: try attacks, test how existing blue-team protocols fare, and see whether the settings produce meaningful signal. Reaching out to teams working on control evaluations (e.g. UKAISI, Redwood Research) for feedback on the pipeline and outputs would also help calibrate quality beyond what an LLM judge can assess.

    - The red-blue co-evolution is a promising direction, but the results are hard to interpret given the small scale. For future projects, consider whether deeper investment in one contribution (e.g. end-to-end validation of the synthetic settings) might produce stronger results than splitting effort across two ambitious pipelines.

    Presentation & Clarity: The paper is well-structured, diagrams add value (although some might be redundant), and the narrative flows cleanly from problem to method to results to caveats. The limitations section is specific and raises relevant shortcomings.

    Read full reviewShow less

Cite this project

@misc{occhipinti2026chiron,
  title = {{Chiron: Agentic Platform for Automated Setting Design and Red-Blue Protocol Optimization in ControlArena}},
  author = {Giovanni Maria Occhipinti},
  year = {2026},
  month = mar,
  note = {Submitted to AI Control Hackathon 2026, an Apart Research Sprint},
  howpublished = {\url{https://apartresearch.com/sprints/projects/chiron-agentic-platform-for-automated-setting-design-and-redblue-protocol-optimization-in-controlarena-52r0}},
  url = {https://apartresearch.com/sprints/projects/chiron-agentic-platform-for-automated-setting-design-and-redblue-protocol-optimization-in-controlarena-52r0}
}

Build something like this at the next Sprint

AI Collusion Research Sprint · Oct 23 - 25, 2026