🚀NEW LABGetting Started with Claude AgentsStart lab
← All papers  /  Sep 30, 2025
Agents

Your Agent May Misevolve: Emergent Risks in Self-evolving LLM Agents

First page
Your Agent May Misevolve: Emergent Risks in Self-evolving LLM Agents
The curator’s take

Self-evolution drifts into unsafe behavior along four paths, which are the model, its memory, its tools and its workflow. The first broad safety study of self-evolving agents, and the counterweight to everything above it.

Ask this paper

Key points
01

Misevolution appears even in agents built on frontier models.

02

Risks emerge from ordinary optimization pressure rather than adversarial input.

Abstract

Advances in Large Language Models (LLMs) have enabled a new class of self-evolving agents that autonomously improve through interaction with the environment, demonstrating strong capabilities. However, self-evolution also introduces novel risks overlooked by current safety research. In this work, we study the case where an agent's self-evolution deviates in unintended ways, leading to undesirable or even harmful outcomes. We refer to this as Misevolution. To provide a systematic investigation, we evaluate misevolution along four key evolutionary pathways: model, memory, tool, and workflow. Our empirical findings reveal that misevolution is a widespread risk, affecting agents built even on top-tier LLMs (e.g., Gemini-2.5-Pro). Different emergent risks are observed in the self-evolutionary process, such as the degradation of safety alignment after memory accumulation, or the unintended introduction of vulnerabilities in tool creation and reuse. To our knowledge, this is the first study to systematically conceptualize misevolution and provide empirical evidence of its occurrence, highlighting an urgent need for new safety paradigms for self-evolving agents. Finally, we discuss potential mitigation strategies to inspire further research on building safer and more trustworthy self-evolving agents. Our code and data are available at https://github.com/ShaoShuai0605/Misevolution . Warning: this paper includes examples that may be offensive or harmful in nature.

Every Monday
Get next week’s papers.
Subscribe on Substack