Hacktoberfest 2026: những issue maintainer đã đánh dấu cho tháng Mười, đang mở và phù hợp người mới. Xem issue Hacktoberfest

BUG: PlagiarismScorer accepts invalid n-gram size and blank reference text

Đã đóng Phù hợp với người mới
#2,971 0 bình luận 0 reaction 0 người được giao Xem trên GitHub

Maintainer thường phản hồi trong vòng 2 ngày

Một pull request liên quan đã được merge.

  • #2972 của @RohithPariki — đã merge

Đánh giá

Độ khó
2/5
Thời gian dự kiến
1-3 giờ
Mức phù hợp với người mới
85/100
Loại issue
Lỗi
Độ rõ ràng
Đặc tả rõ ràng
Mức độ hoạt động
Sôi nổi
Công nghệ
python
Lĩnh vực
security

Hướng nghiên cứu

Bắt đầu trong pyrit/score/float_scale/plagiarism_scorer.py tại PlagiarismScorer.init, sau đó so sánh cách xử lý tham số của nó với phần validation của ApproximateTextMatching được mô tả trong issue. Chạy các test PlagiarismScorer hiện có và bổ sung coverage cho n không hợp lệ, văn bản tham chiếu trống và các metric không hợp lệ; hoàn thành khi quá trình khởi tạo từ chối từng trường hợp được liệt kê mà không thay đổi việc scoring hợp lệ.

Do mô hình lập chỉ mục viết ra từ nội dung của issue.

Mô tả

Describe the bug

PlagiarismScorer does not validate its n (n-gram size) or reference_text parameters during initialization.

  1. n <= 0 creates false-positive 100% plagiarism matches:
    When n = 0, _ngram_set returns {()} (an empty tuple). In PlagiarismMetric.JACCARD, len(ref_ngrams & res_ngrams) / len(ref_ngrams) evaluates to 1 / 1 = 1.0 for any response. A completely unrelated prompt response is therefore reported as 100% plagiarized.
    When n < 0 (e.g. n = -1), negative slicing produces spurious n-grams and invalid partial overlap scores (e.g. 0.5).
    When n is a non-integer float (e.g. 2.5), construction succeeds, but scoring later crashes with TypeError: 'float' object cannot be interpreted as an integer.
    When n is a boolean (e.g. False), it evaluates as 0 and yields the same false-positive 1.0.

  2. Empty or whitespace-only reference_text silently reports 0.0 for all responses:
    When reference_text is "" or whitespace-only " ", _tokenize(reference) produces [] (reference_len = 0). The condition response_len == 0 or reference_len == 0 causes _plagiarism_score to silently return 0.0 for every response, even when the response is identical to the reference text. A static misconfiguration is thus silently swallowed and reported as non-plagiarism.

The sibling class in analytics, ApproximateTextMatching, already validates that its n-gram parameter n must be an integer >= 1.

Steps/Code to Reproduce

from pyrit.score import PlagiarismScorer, PlagiarismMetric

# 1. n=0 scores 1.0 (100% match) for completely unrelated text
scorer = PlagiarismScorer(
    reference_text="The quick brown fox jumps over the lazy dog",
    metric=PlagiarismMetric.JACCARD,
    n=0,
)
score = scorer._plagiarism_score(
    response="Completely unrelated content about astrophysics and quantum mechanics",
    reference="The quick brown fox jumps over the lazy dog",
    metric=PlagiarismMetric.JACCARD,
    n=0,
)
print("Score with n=0:", score)

# 2. n=-1 yields spurious partial match
print(
    "Score with n=-1:",
    scorer._plagiarism_score(
        response="Completely unrelated content",
        reference="The quick brown fox jumps over the lazy dog",
        metric=PlagiarismMetric.JACCARD,
        n=-1,
    ),
)

# 3. Empty reference_text silently evaluates every response as 0.0
empty_scorer = PlagiarismScorer(reference_text="", metric=PlagiarismMetric.LCS)
print("Score with empty reference:", empty_scorer._plagiarism_score(response="", reference=""))

Expected Results

PlagiarismScorer.__init__ should validate parameters at construction time and raise ValueError:

  • reference_text must be a non-empty string containing at least one word token.
  • n must be an integer >= 1 (rejecting 0, negative values, booleans, and non-integers).
  • metric must be an instance of PlagiarismMetric.

Actual Results

Score with n=0: 1.0
Score with n=-1: 0.5
Score with empty reference: 0.0

PlagiarismScorer.__init__ assigns self.reference_text = reference_text and self.n = n directly at pyrit/score/float_scale/plagiarism_scorer.py:54-56 without validation.

Versions

  • OS: Windows 11
  • Python: 3.14
  • PyRIT: main at c2ae5eeb
Ngôn ngữ chính
Python
Star
4.6k
Fork
944
Merge trung bình
3 ngày 4 giờ
Pull request đã merge (30 ngày)
264

Chuẩn bị môi trường

Mở trong Codespaces

Khởi chạy dev container của dự án ngay trên trình duyệt, bằng tài khoản GitHub của bạn.

  • Không có Dockerfile hay tệp Docker Compose
  • Có mẫu pull request
  • Không có hướng dẫn đóng góp

Bắt đầu từ đâu

  1. Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
  2. Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
  3. Fork repository và làm thay đổi trên một nhánh.
  4. Mở pull request có tham chiếu số hiệu của issue.

Issue khác của microsoft/PyRIT

Tất cả issue của microsoft/PyRIT

Issue tương tự

Thêm issue về Python

Nhận issue mới trong hộp thư của bạn

Bản tóm tắt ngắn những issue GitHub phù hợp với người mới.