Evidence map›Paper›PMID 41917231›Full record

ArticleScientific reports2026

Toward trustworthy chatbots: a protocol for red teaming for health related conversations.

Syed-Amad Hussain, Daniel I Jackson, Ashley Lewis, Eric Fosler-Lussier, Emre Sezgin

Abstract read
In one paragraph

Article in Scientific reports, 2026. The graph could read no effect estimate from its abstract, so it casts no vote on the map. Not yet cited in PubMed.

0numbers the graph read from it
0cells of the map it votes in
0citing papers in PubMed
–field-weighted citation impact
1 · What the graph read from it

What it found

Each row is one number read from the abstract, on the scale the paper reported it, with its interval. Left of the dashed line favours the treatment, right favours the comparator. Under each row is the sentence it came from. New to these charts? A ten-minute tutorial.

The abstract states no effect estimate the extractor could read, or names no intervention and outcome on the map, so this paper lights no cell and moves no belief. It is still indexed, cited and linked below.

2 · The registry

The trial behind it

Trials whose registry record cites this paper, or whose number appears in the abstract. A trial that started after this paper was published is citing it as background, not reporting it.

Neither the registry nor the abstract names a trial number. If this is a trial report, that itself is worth knowing.

3 · Its place in the literature

Who cites it

0 citing papers in PubMed.

No citing paper in PubMed yet.

4 · The record

Corrections and comments

5 · Who and what money

Authors and funding

5 authors.

Syed-Amad HussainAbigail Wexner Research Institute at Nationwide Children's Hospital, 700 Children's Dr, Columbus, OH, 43205, USA. amad.hussain@nationwidechildrens.org.
Daniel I JacksonAbigail Wexner Research Institute at Nationwide Children's Hospital, 700 Children's Dr, Columbus, OH, 43205, USA.
Ashley LewisDepartment of Linguistics, The Ohio State University, Columbus, OH, USA.
Eric Fosler-LussierAbigail Wexner Research Institute at Nationwide Children's Hospital, 700 Children's Dr, Columbus, OH, 43205, USA.
Emre SezginAbigail Wexner Research Institute at Nationwide Children's Hospital, 700 Children's Dr, Columbus, OH, 43205, USA.

Funding

National Center for Advancing Translational Sciences of the National Institutes of Health UM1TR004548
6 · The paper itself

Abstract

Health-related chatbots require safety assurance beyond factual correctness. We propose a red-teaming protocol for patient-facing AI structured around three pillars: error stratification, dual-pronged testing, and vulnerability-informed mitigation. We distinguish Document Adherence (DA) from Instruction Adherence (IA), deploying adversarial “attacks” across both single-turn and multi-turn exchanges to provoke system failures. We then applied layered mitigations informed by the vulnerabilities revealed by these attacks. We evaluate this framework on a retrieval-augmented generation (RAG) based chatbot designed to assist with health-related social needs (HRSN).The protocol identified behavioral noncompliance as the dominant risk. While robust in DA (0/60 errors), the system struggled with IA (15% error rate). Crucially, multi-turn stress tests revealed vulnerabilities hidden in single-turn checks: error rates spiked to 50% for advice queries and 40% for user distress. All high-severity failures occurred during these sustained interactions. Of our mitigations, prompt augmentation reduced total errors by 60%, while document augmentation mitigated single-turn distress errors. Combined, they eliminated high-severity errors entirely by forcing “safe failure” loops. We suggest this cycle of stratified analysis, depth-based testing, and targeted mitigation can be a guiding framework for securing clinical conversational agents.

Indexed as

CommunicationGenerative Artificial IntelligenceMedical InformaticsHumans

Identifiers

PMID41917231
PMCPMC13187206

What Socratic holds

Textmetadata
LicenceCC BY-NC-ND
Read underepoch 390

Registered trials

None linked

Read under generation 80e0d062 · epoch 390. Bibliography from PubMed, PubMed Central and OpenAlex; grants from NIH RePORTER; trial links from ClinicalTrials.gov; estimates, votes and beliefs from the Socratic graph.