An Early Warning of Emerging Biosecurity Risks in Frontier LLMs

StatsAreFun1 pts0 comments

[2607.18056] An Early Warning of Emerging Biosecurity Risks in Frontier LLMs

Skip to main content

Search arXiv

Press Enter to search · Advanced search

-->

Computer Science > Computation and Language

arXiv:2607.18056 (cs)

[Submitted on 20 Jul 2026]

Title:An Early Warning of Emerging Biosecurity Risks in Frontier LLMs

Authors:Zhida He, Xia Hu, Baichen Le, Chunxiao Li, Jiajia Li, Lijun Li, Chaochao Lu, Jing Shao, Youbang Sun, Hua Tang, Xiang Wang, Xiao Wang, Xiaoyu Wen, Tong Wu, Jia Xu, Peng Yu, Shu Yu, Jie Zhang, Qiaosheng Zhang, Yi Zhang, Xing-Ming Zhao, Tianhang Zheng, Ziyuan Zhou<br>View a PDF of the paper titled An Early Warning of Emerging Biosecurity Risks in Frontier LLMs, by Zhida He and 22 other authors

View PDF

Abstract:Frontier large language models (LLMs) are increasingly integrated into scientific workflows, yet their growing biological capabilities may outpace current safeguards. To assess the biological risks of frontier models, we develop Intern-BioBreaker, a specialized bio-red-teaming model, together with an integrated computational-to-physical framework that couples model-level stress testing with wet-lab validation. Within this framework, Intern-BioBreaker generates targeted jailbreak prompts to test whether aligned models can be induced to provide operational guidance for safety-sensitive biological tasks or produce sequence-level outputs with potentially harmful properties. Selected sequence outputs are then carried forward for DNA synthesis, host expression, and orthogonal protein verification to assess whether model-generated designs can yield the intended biological products. Our evaluation reveals a concerning gap between text-level safeguards and the risks posed by capable scientific models: (i) Intern-BioBreaker outperforms baseline attack models and reveals widespread bio-risk jailbreak vulnerabilities across both open-weight and proprietary frontier LLMs, with several targets reaching near-saturated or 100% task-level attack success rate (ASR); (ii) in sequence-level case studies, GPT-5.5 can be induced to generate modified viral candidate sequences with pathogenic potential; the corresponding translated proteins may exhibit even stronger receptor-binding affinity and thus enhanced infection potential; and (iii) end-to-end verification shows that selected model-generated biological designs are not merely textual artifacts, but can be physically realized under controlled experimental settings. These findings underscore the need for stronger biological red-teaming, nucleic acid synthesis screening, and safety mechanisms that keep pace with model capabilities.

Comments:<br>22 pages, 7 figures, authors are listed alphabetically by surname

Subjects:

Computation and Language (cs.CL); Genomics (q-bio.GN)

Cite as:<br>arXiv:2607.18056 [cs.CL]

(or<br>arXiv:2607.18056v1 [cs.CL] for this version)

https://doi.org/10.48550/arXiv.2607.18056

Focus to learn more

arXiv-issued DOI via DataCite (pending registration)

Submission history<br>From: Tong Wu [view email]<br>[v1]<br>Mon, 20 Jul 2026 15:26:23 UTC (8,910 KB)

Full-text links:<br>Access Paper:

View a PDF of the paper titled An Early Warning of Emerging Biosecurity Risks in Frontier LLMs, by Zhida He and 22 other authors<br>View PDF<br>TeX Source

view license

Current browse context:

cs.CL

next >

new<br>recent<br>| 2026-07

Change to browse by:

cs<br>q-bio<br>q-bio.GN

References & Citations

NASA ADS<br>Google Scholar

Semantic Scholar

export BibTeX citation<br>Loading...

BibTeX formatted citation

&times;

loading...

Data provided by:

Bookmark

Bibliographic Tools

Bibliographic and Citation Tools

Bibliographic Explorer Toggle

Bibliographic Explorer (What is the Explorer?)

Connected Papers Toggle

Connected Papers (What is Connected Papers?)

Litmaps Toggle

Litmaps (What is Litmaps?)

scite.ai Toggle

scite Smart Citations (What are Smart Citations?)

Code, Data, Media

Code, Data and Media Associated with this Article

alphaXiv Toggle

alphaXiv (What is alphaXiv?)

Links to Code Toggle

CatalyzeX Code Finder for Papers (What is CatalyzeX?)

DagsHub Toggle

DagsHub (What is DagsHub?)

GotitPub Toggle

Gotit.pub (What is GotitPub?)

Huggingface Toggle

Hugging Face (What is Huggingface?)

ScienceCast Toggle

ScienceCast (What is ScienceCast?)

Demos

Demos

Replicate Toggle

Replicate (What is Replicate?)

Spaces Toggle

Hugging Face Spaces (What is Spaces?)

Spaces Toggle

TXYZ.AI (What is TXYZ.AI?)

Related Papers

Recommenders and Search Tools

Link to Influence Flower

Influence Flower (What are Influence Flowers?)

Core recommender toggle

CORE Recommender (What is CORE?)

Author

Venue

Institution

Topic

About arXivLabs

arXivLabs: experimental projects with community collaborators

arXivLabs is a framework that allows collaborators to develop and share new arXiv features directly on our website.

Both individuals and organizations that work with arXivLabs have embraced and accepted our values of openness, community, excellence, and user...

toggle frontier risks llms arxiv view

Related Articles