microsoft / microsoft/PyRIT

Parent: LLM Vulnerability Scanner Feature Parity with Garak, Giskard, CyberSecEval

Đang mở
#511 2 bình luận 2 reaction 0 người được giao Xem trên GitHub

Chưa có ai nhận issue này.

good first issue help wanted
Ngôn ngữ chính
Python
Star
4.5k
Fork
893
Merge trung bình
3 ngày 50 phút
Pull request đã merge (30 ngày)
165

Mô tả

TLDR; We want help creating issues where Garak, Giskard, or CyberSecEval support an attack scenario where PyRIT doesn't support it.

#### Background

Other tools like Garak, Giskard, and CyberSecEval have different use cases from PyRIT, but there is overlap as well. If there is an attack in one of these other platforms, we probably want to support it also and would love issues being created so we can track this (or clarify if it already exists/improve our docs).

[This](https://arxiv.org/abs/2410.16527) paper tackles a really difficult problem, and that's comparing these tools (and PyRIT). When I was looking, some of the things I noticed that it mentioned PyRIT was lacking were:

- Lack of multi-language support (I think we actually have this as a converter)
- Lack of GCG (we have this as an auxiliary module)
- Dan, AutoDan, etc (I think we have support for all of this. We certainly have DAN and ways to modify those prompts with GPTFuzz - but we would love to know what we're missing)
- Insecure Coding Test (we don't have this, but it would be an easy scorer to write!)

And there might be more that I missed!

So as an example of issues we'd like, all of the above are good to open. Even if we think we support them (like in the multi-language case) we can dive into specifics to make sure we're not missing anything, and potentially improve documentation so it's more obvious these scenarios are supported.

#### Describe the solution you'd like

Please open follow-up sub-issues with any features you notice or find in these other tools that PyRIT doesn't have! That way we can track them. Also, we would love community to tackle any of these also, but it still can be helpful to open an issue so we can help guide :D

Hướng dẫn đóng góp

Chưa lập chỉ mục được hướng dẫn đóng góp cho kho mã nguồn này

Bắt đầu từ đâu

  1. Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
  2. Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
  3. Fork repository và làm thay đổi trên một nhánh.
  4. Mở pull request có tham chiếu số hiệu của issue.

Hướng nghiên cứu

Chưa xác định được tệp triển khai, bài kiểm thử hoặc điểm vào nào. Hãy bắt đầu bằng cách so sánh các kịch bản tấn công được Garak, Giskard và CyberSecEval hỗ trợ với các khả năng đã được tài liệu hóa của PyRIT, sau đó mở một issue theo dõi tập trung vào một kịch bản còn thiếu; được coi là hoàn tất khi kịch bản đó có phạm vi triển khai hoặc tài liệu rõ ràng.

Do mô hình lập chỉ mục viết ra từ nội dung của issue.

Đánh giá

Công nghệ
python
Lĩnh vực
security
Loại issue
Tính năng
Độ khó
5/5
Thời gian dự kiến
Hơn một tuần
Mức độ hoạt động
Ít trao đổi
Độ rõ ràng
Cần làm rõ
Mức phù hợp với người mới
25/100

Nhận issue mới trong hộp thư của bạn

Bản tóm tắt ngắn những issue GitHub phù hợp với người mới.