{"id":"https://openalex.org/W7143403429","doi":"https://doi.org/10.48550/arxiv.2603.25747","title":"BeSafe-Bench: Unveiling Behavioral Safety Risks of Situated Agents in Functional Environments","display_name":"BeSafe-Bench: Unveiling Behavioral Safety Risks of Situated Agents in Functional Environments","publication_year":2026,"publication_date":"2026-01-30","ids":{"openalex":"https://openalex.org/W7143403429","doi":"https://doi.org/10.48550/arxiv.2603.25747"},"language":null,"primary_location":{"id":"doi:10.48550/arxiv.2603.25747","is_oa":true,"landing_page_url":"https://doi.org/10.48550/arxiv.2603.25747","pdf_url":null,"source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":null,"is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"article"},"type":"preprint","indexed_in":["datacite"],"open_access":{"is_oa":true,"oa_status":"green","oa_url":"https://doi.org/10.48550/arxiv.2603.25747","any_repository_has_fulltext":true},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5130956236","display_name":"Yuxuan Li","orcid":null},"institutions":[],"countries":[],"is_corresponding":true,"raw_author_name":"Li, Yuxuan","raw_affiliation_strings":[],"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5130994073","display_name":"Yi Lin","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Lin, Yi","raw_affiliation_strings":[],"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5130978294","display_name":"Peng Wang","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Wang, Peng","raw_affiliation_strings":[],"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5100692291","display_name":"Shimin Liu","orcid":"https://orcid.org/0000-0001-9612-0047"},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Liu, Shiming","raw_affiliation_strings":[],"affiliations":[]},{"author_position":"last","author":{"id":"https://openalex.org/A5130999500","display_name":"Xuetao Wei","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Wei, Xuetao","raw_affiliation_strings":[],"affiliations":[]}],"institutions":[],"countries_distinct_count":0,"institutions_distinct_count":5,"corresponding_author_ids":["https://openalex.org/A5130956236"],"corresponding_institution_ids":[],"apc_list":null,"apc_paid":null,"fwci":null,"has_fulltext":false,"cited_by_count":0,"citation_normalized_percentile":null,"cited_by_percentile_year":null,"biblio":{"volume":null,"issue":null,"first_page":null,"last_page":null},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T10525","display_name":"Human-Automation Interaction and Safety","score":0.1315000057220459,"subfield":{"id":"https://openalex.org/subfields/3207","display_name":"Social Psychology"},"field":{"id":"https://openalex.org/fields/32","display_name":"Psychology"},"domain":{"id":"https://openalex.org/domains/2","display_name":"Social Sciences"}},"topics":[{"id":"https://openalex.org/T10525","display_name":"Human-Automation Interaction and Safety","score":0.1315000057220459,"subfield":{"id":"https://openalex.org/subfields/3207","display_name":"Social Psychology"},"field":{"id":"https://openalex.org/fields/32","display_name":"Psychology"},"domain":{"id":"https://openalex.org/domains/2","display_name":"Social Sciences"}},{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.10379999876022339,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T13295","display_name":"Safety Systems Engineering in Autonomy","score":0.08879999816417694,"subfield":{"id":"https://openalex.org/subfields/2213","display_name":"Safety, Risk, Reliability and Quality"},"field":{"id":"https://openalex.org/fields/22","display_name":"Engineering"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/situated","display_name":"Situated","score":0.859499990940094},{"id":"https://openalex.org/keywords/embodied-cognition","display_name":"Embodied cognition","score":0.630299985408783},{"id":"https://openalex.org/keywords/software-deployment","display_name":"Software deployment","score":0.6262000203132629},{"id":"https://openalex.org/keywords/task","display_name":"Task (project management)","score":0.6019999980926514},{"id":"https://openalex.org/keywords/benchmark","display_name":"Benchmark (surveying)","score":0.5690000057220459},{"id":"https://openalex.org/keywords/construct","display_name":"Construct (python library)","score":0.5602999925613403},{"id":"https://openalex.org/keywords/space","display_name":"Space (punctuation)","score":0.39660000801086426},{"id":"https://openalex.org/keywords/domain","display_name":"Domain (mathematical analysis)","score":0.34200000762939453}],"concepts":[{"id":"https://openalex.org/C132829578","wikidata":"https://www.wikidata.org/wiki/Q581151","display_name":"Situated","level":2,"score":0.859499990940094},{"id":"https://openalex.org/C100609095","wikidata":"https://www.wikidata.org/wiki/Q1335050","display_name":"Embodied cognition","level":2,"score":0.630299985408783},{"id":"https://openalex.org/C105339364","wikidata":"https://www.wikidata.org/wiki/Q2297740","display_name":"Software deployment","level":2,"score":0.6262000203132629},{"id":"https://openalex.org/C2780451532","wikidata":"https://www.wikidata.org/wiki/Q759676","display_name":"Task (project management)","level":2,"score":0.6019999980926514},{"id":"https://openalex.org/C185798385","wikidata":"https://www.wikidata.org/wiki/Q1161707","display_name":"Benchmark (surveying)","level":2,"score":0.5690000057220459},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.5676000118255615},{"id":"https://openalex.org/C2780801425","wikidata":"https://www.wikidata.org/wiki/Q5164392","display_name":"Construct (python library)","level":2,"score":0.5602999925613403},{"id":"https://openalex.org/C112930515","wikidata":"https://www.wikidata.org/wiki/Q4389547","display_name":"Risk analysis (engineering)","level":1,"score":0.4844000041484833},{"id":"https://openalex.org/C107457646","wikidata":"https://www.wikidata.org/wiki/Q207434","display_name":"Human\u2013computer interaction","level":1,"score":0.42489999532699585},{"id":"https://openalex.org/C2778572836","wikidata":"https://www.wikidata.org/wiki/Q380933","display_name":"Space (punctuation)","level":2,"score":0.39660000801086426},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.3564999997615814},{"id":"https://openalex.org/C36503486","wikidata":"https://www.wikidata.org/wiki/Q11235244","display_name":"Domain (mathematical analysis)","level":2,"score":0.34200000762939453},{"id":"https://openalex.org/C136197465","wikidata":"https://www.wikidata.org/wiki/Q1729295","display_name":"Variety (cybernetics)","level":2,"score":0.30790001153945923},{"id":"https://openalex.org/C165696696","wikidata":"https://www.wikidata.org/wiki/Q11287","display_name":"Exploit","level":2,"score":0.3003999888896942},{"id":"https://openalex.org/C175154964","wikidata":"https://www.wikidata.org/wiki/Q380077","display_name":"Task analysis","level":3,"score":0.2994000017642975},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.2946999967098236},{"id":"https://openalex.org/C142944206","wikidata":"https://www.wikidata.org/wiki/Q1786137","display_name":"Proactivity","level":2,"score":0.28450000286102295},{"id":"https://openalex.org/C2989277270","wikidata":"https://www.wikidata.org/wiki/Q168338","display_name":"Behavioral analysis","level":2,"score":0.2833000123500824},{"id":"https://openalex.org/C78639753","wikidata":"https://www.wikidata.org/wiki/Q3318160","display_name":"Behavioral modeling","level":2,"score":0.2777999937534332},{"id":"https://openalex.org/C132835097","wikidata":"https://www.wikidata.org/wiki/Q7663745","display_name":"System safety","level":2,"score":0.27480000257492065},{"id":"https://openalex.org/C74072328","wikidata":"https://www.wikidata.org/wiki/Q1142726","display_name":"Intelligent agent","level":2,"score":0.2705000042915344},{"id":"https://openalex.org/C56739046","wikidata":"https://www.wikidata.org/wiki/Q192060","display_name":"Knowledge management","level":1,"score":0.26440000534057617},{"id":"https://openalex.org/C3017944768","wikidata":"https://www.wikidata.org/wiki/Q1450463","display_name":"Poison control","level":2,"score":0.2630999982357025},{"id":"https://openalex.org/C168167062","wikidata":"https://www.wikidata.org/wiki/Q1117970","display_name":"Component (thermodynamics)","level":2,"score":0.26089999079704285},{"id":"https://openalex.org/C2780791683","wikidata":"https://www.wikidata.org/wiki/Q846785","display_name":"Action (physics)","level":2,"score":0.2572000026702881}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.48550/arxiv.2603.25747","is_oa":true,"landing_page_url":"https://doi.org/10.48550/arxiv.2603.25747","pdf_url":null,"source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":null,"is_accepted":false,"is_published":null,"raw_source_name":null,"raw_type":"article"}],"best_oa_location":{"id":"doi:10.48550/arxiv.2603.25747","is_oa":true,"landing_page_url":"https://doi.org/10.48550/arxiv.2603.25747","pdf_url":null,"source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":null,"is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"article"},"sustainable_development_goals":[],"awards":[],"funders":[],"has_content":{"grobid_xml":false,"pdf":false},"content_urls":null,"referenced_works_count":0,"referenced_works":[],"related_works":[],"abstract_inverted_index":{"The":[0],"rapid":[1],"evolution":[2],"of":[3,33,70,102,139],"Large":[4],"Multimodal":[5],"Models":[6],"(LMMs)":[7],"has":[8],"enabled":[9],"agents":[10,72,126],"to":[11,118,144],"perform":[12],"complex":[13],"digital":[14],"and":[15,84,105,147],"physical":[16],"tasks,":[17],"yet":[18],"their":[19],"deployment":[20],"as":[21,42],"autonomous":[22],"decision-makers":[23],"introduces":[24],"substantial":[25],"unintentional":[26],"behavioral":[27,67],"safety":[28,36,68,145,155,165],"risks.":[29],"However,":[30],"the":[31,132,160],"absence":[32],"a":[34,39,63,92,107,128],"comprehensive":[35],"benchmark":[37,64],"remains":[38],"major":[40],"bottleneck,":[41],"existing":[43],"evaluations":[44],"rely":[45],"on":[46],"low-fidelity":[47],"environments,":[48,75,89],"simulated":[49],"APIs,":[50],"or":[51],"narrowly":[52],"scoped":[53],"tasks.":[54],"To":[55],"address":[56],"this":[57],"gap,":[58],"we":[59,90],"present":[60],"BeSafe-Bench":[61],"(BSB),":[62],"for":[65,163],"exposing":[66],"risks":[69],"situated":[71],"in":[73,171],"functional":[74,88],"covering":[76],"four":[77],"representative":[78],"domains:":[79],"Web,":[80],"Mobile,":[81],"Embodied":[82,85],"VLM,":[83],"VLA.":[86],"Using":[87],"construct":[91],"diverse":[93],"instruction":[94],"space":[95],"by":[96],"augmenting":[97],"tasks":[98,140],"with":[99,115,153],"nine":[100],"categories":[101],"safety-critical":[103],"risks,":[104],"adopt":[106],"hybrid":[108],"evaluation":[109],"framework":[110],"that":[111],"combines":[112],"rule-based":[113],"checks":[114],"LLM-as-a-judge":[116],"reasoning":[117],"assess":[119],"real":[120],"environmental":[121],"impacts.":[122],"Evaluating":[123],"13":[124],"popular":[125],"reveals":[127],"concerning":[129],"trend:":[130],"even":[131],"best-performing":[133],"agent":[134],"completes":[135],"fewer":[136],"than":[137],"40%":[138],"while":[141],"fully":[142],"adhering":[143],"constraints,":[146],"strong":[148],"task":[149],"performance":[150],"frequently":[151],"coincides":[152],"severe":[154],"violations.":[156],"These":[157],"findings":[158],"underscore":[159],"urgent":[161],"need":[162],"improved":[164],"alignment":[166],"before":[167],"deploying":[168],"agentic":[169],"systems":[170],"real-world":[172],"settings.":[173]},"counts_by_year":[],"updated_date":"2026-03-31T06:07:48.031334","created_date":"2026-03-31T00:00:00"}
