Hacktoberfest 2026: le issue che i maintainer hanno segnato per ottobre, aperte e adatte ai principianti. Sfoglia le issue Hacktoberfest

BUG: PlagiarismScorer accepts invalid n-gram size and blank reference text

Aperta Adatta ai principianti
#2,971 0 commenti 0 reazioni 0 assegnatari Vedi su GitHub

I maintainer di solito rispondono entro 2 giorni

@RohithPariki ci sta già lavorando.

Dal 3/10/2026.

  • #2972 di @RohithPariki — aperta

Valutazione

Difficoltà
2/5
Tempo stimato
1-3 ore
Idoneità per principianti
85/100
Tipo di issue
Bug
Chiarezza
Specificata chiaramente
Stato di attività
Attiva
Stack tecnologico
python
Ambito
security

Direzione di ricerca

Inizia in pyrit/score/float_scale/plagiarism_scorer.py, in PlagiarismScorer.init, quindi confronta la gestione dei parametri con la validazione di ApproximateTextMatching descritta nell’issue. Esegui i test esistenti di PlagiarismScorer e aggiungi la copertura per n non valido, testo di riferimento vuoto e metriche non valide; il lavoro è completo quando la costruzione rifiuta ciascun caso elencato senza modificare il punteggio valido.

Scritto dal modello di indicizzazione a partire dal testo della issue.

Descrizione

Describe the bug

PlagiarismScorer does not validate its n (n-gram size) or reference_text parameters during initialization.

  1. n <= 0 creates false-positive 100% plagiarism matches:
    When n = 0, _ngram_set returns {()} (an empty tuple). In PlagiarismMetric.JACCARD, len(ref_ngrams & res_ngrams) / len(ref_ngrams) evaluates to 1 / 1 = 1.0 for any response. A completely unrelated prompt response is therefore reported as 100% plagiarized.
    When n < 0 (e.g. n = -1), negative slicing produces spurious n-grams and invalid partial overlap scores (e.g. 0.5).
    When n is a non-integer float (e.g. 2.5), construction succeeds, but scoring later crashes with TypeError: 'float' object cannot be interpreted as an integer.
    When n is a boolean (e.g. False), it evaluates as 0 and yields the same false-positive 1.0.

  2. Empty or whitespace-only reference_text silently reports 0.0 for all responses:
    When reference_text is "" or whitespace-only " ", _tokenize(reference) produces [] (reference_len = 0). The condition response_len == 0 or reference_len == 0 causes _plagiarism_score to silently return 0.0 for every response, even when the response is identical to the reference text. A static misconfiguration is thus silently swallowed and reported as non-plagiarism.

The sibling class in analytics, ApproximateTextMatching, already validates that its n-gram parameter n must be an integer >= 1.

Steps/Code to Reproduce

from pyrit.score import PlagiarismScorer, PlagiarismMetric

# 1. n=0 scores 1.0 (100% match) for completely unrelated text
scorer = PlagiarismScorer(
    reference_text="The quick brown fox jumps over the lazy dog",
    metric=PlagiarismMetric.JACCARD,
    n=0,
)
score = scorer._plagiarism_score(
    response="Completely unrelated content about astrophysics and quantum mechanics",
    reference="The quick brown fox jumps over the lazy dog",
    metric=PlagiarismMetric.JACCARD,
    n=0,
)
print("Score with n=0:", score)

# 2. n=-1 yields spurious partial match
print(
    "Score with n=-1:",
    scorer._plagiarism_score(
        response="Completely unrelated content",
        reference="The quick brown fox jumps over the lazy dog",
        metric=PlagiarismMetric.JACCARD,
        n=-1,
    ),
)

# 3. Empty reference_text silently evaluates every response as 0.0
empty_scorer = PlagiarismScorer(reference_text="", metric=PlagiarismMetric.LCS)
print("Score with empty reference:", empty_scorer._plagiarism_score(response="", reference=""))

Expected Results

PlagiarismScorer.__init__ should validate parameters at construction time and raise ValueError:

  • reference_text must be a non-empty string containing at least one word token.
  • n must be an integer >= 1 (rejecting 0, negative values, booleans, and non-integers).
  • metric must be an instance of PlagiarismMetric.

Actual Results

Score with n=0: 1.0
Score with n=-1: 0.5
Score with empty reference: 0.0

PlagiarismScorer.__init__ assigns self.reference_text = reference_text and self.n = n directly at pyrit/score/float_scale/plagiarism_scorer.py:54-56 without validation.

Versions

  • OS: Windows 11
  • Python: 3.14
  • PyRIT: main at c2ae5eeb
Lingua principale
Python
Stelle
4.6k
Fork
924
Merge medio
2g 14h
PR unite (30g)
227

Preparare l'ambiente

Apri in Codespaces

Avvia il container di sviluppo del progetto nel browser, con il tuo account GitHub.

  • Nessun Dockerfile né file Docker Compose
  • Ha un modello di pull request
  • Nessuna guida per i contributori

Come iniziare

  1. Leggi tutta la issue e poi la guida ai contributi del progetto.
  2. Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
  3. Fai un fork del repository e lavora su un branch.
  4. Apri una pull request che faccia riferimento al numero della issue.

Altre issue di microsoft/PyRIT

Tutte le issue di microsoft/PyRIT

Issue simili

Altre issue su Python

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.