microsoft / microsoft/PyRIT

Parent: LLM Vulnerability Scanner Feature Parity with Garak, Giskard, CyberSecEval

Ouverte
#511 2 commentaires 2 réactions 0 personnes assignées Voir sur GitHub

Personne n'a encore pris cette issue.

good first issue help wanted
Langage dominant
Python
Étoiles
4.5k
Forks
893
Merge moyen
3 j 50 min
PR mergées (30 j)
165

Description

TLDR; We want help creating issues where Garak, Giskard, or CyberSecEval support an attack scenario where PyRIT doesn't support it.

#### Background

Other tools like Garak, Giskard, and CyberSecEval have different use cases from PyRIT, but there is overlap as well. If there is an attack in one of these other platforms, we probably want to support it also and would love issues being created so we can track this (or clarify if it already exists/improve our docs).

[This](https://arxiv.org/abs/2410.16527) paper tackles a really difficult problem, and that's comparing these tools (and PyRIT). When I was looking, some of the things I noticed that it mentioned PyRIT was lacking were:

- Lack of multi-language support (I think we actually have this as a converter)
- Lack of GCG (we have this as an auxiliary module)
- Dan, AutoDan, etc (I think we have support for all of this. We certainly have DAN and ways to modify those prompts with GPTFuzz - but we would love to know what we're missing)
- Insecure Coding Test (we don't have this, but it would be an easy scorer to write!)

And there might be more that I missed!

So as an example of issues we'd like, all of the above are good to open. Even if we think we support them (like in the multi-language case) we can dive into specifics to make sure we're not missing anything, and potentially improve documentation so it's more obvious these scenarios are supported.

#### Describe the solution you'd like

Please open follow-up sub-issues with any features you notice or find in these other tools that PyRIT doesn't have! That way we can track them. Also, we would love community to tackle any of these also, but it still can be helpful to open an issue so we can help guide :D

Guide de contribution

Aucun guide de contribution indexé pour ce dépôt

Par où commencer

  1. Lisez l'issue en entier, puis le guide de contribution du projet.
  2. Signalez en commentaire que vous la prenez — cela évite que deux personnes fassent le même travail.
  3. Forkez le dépôt et travaillez sur une branche.
  4. Ouvrez une pull request qui référence le numéro de l'issue.

Piste de recherche

Aucun fichier d’implémentation, test ou point d’entrée n’est identifié. Commencez par comparer les scénarios d’attaque pris en charge par Garak, Giskard et CyberSecEval avec les capacités documentées de PyRIT, puis ouvrez une issue de suivi ciblée pour un scénario manquant ; le travail est considéré comme terminé lorsque le scénario possède un périmètre clair d’implémentation ou de documentation.

Rédigé par le modèle d'indexation à partir du texte de l'issue.

Évaluation

Stack technique
python
Domaine
security
Type d'issue
Fonctionnalité
Difficulté
5/5
Temps estimé
Plus d'une semaine
Activité
Calme
Clarté
À clarifier
Accessibilité débutants
25/100

Recevez les nouvelles issues par e-mail

Un résumé court des issues GitHub adaptées aux débutants.