OpenAI's Self-Play Red Team Flywheel
imjustnewatai · x · 2026-07-16
This piece discusses how OpenAI seems to have demonstrated a language model self-play loop similar to AlphaZero:
- GPT-Red is trained via self-play: one side attacks while another group of models defends.
- In new prompt injection scenarios targeting GPT-5.1, GPT-Red achieved an 84% successful attack rate, compared to only 13% by human red teamers.
- OpenAI then used the attack samples found by GPT-Red to train GPT-5.6 Sol, which the author claims reduced the failure rate against GPT-Red's direct prompt injections to 0.05%.
The author speculates that this "attack-patch-attack" flywheel could eventually extend from post-training to pre-training: models participating in generating and validating training data, designing harder curricula, optimizing the training process, and even helping build next-generation models.
However, he also cautions:
- It is not yet "models training themselves"; humans still set the goals, environments, and scoring criteria.
- OpenAI also believes GPT-5.6 has not yet reached its defined "High" self-improvement threshold.
- Uncontrolled synthetic data loops could reduce diversity and actually harm the model.
Related event: OpenAI unveils automated red-teaming system GPT-Red(16 posts)→
More from Models
- AI Sextet offers 6 models free and unlimited for 14 days, including DeepSeek and Qwen — airesearch12 · 2026-09-11
- BullshitBench update: GPT-6-Astra beats all prior OpenAI models but still trails Anthropic — scaling01 · 2026-09-11
- Astra Scores 83% on GauntletBench, First Computer-Use Agent to Beat Human Baseline — ducha_aiki · 2026-09-11
- Kimi K2.8 Preview rolls out: near-K3 coding performance, 1M context for all tiers — teortaxesTex · 2026-09-11
- Looking for a classifier of software engineering task shapes to pick models per task — StewartalsopIII · 2026-09-11
- DeepSeek V4 Pro API to continue after Sept 2026, billing unchanged — teortaxesTex · 2026-09-11