Suggestion: Built-in test scenarios for RAG retrieval poisoning
还没有人认领这个 Issue。
评估
调研方向
首先检查 PyRIT 现有的测试场景模块,以及与检索相关的向量存储或 RAG 集成点。定义应如何模拟和测量有毒文档注入及其对生成响应的影响;当 framework 包含一个用于评估检索投毒的、有文档记录且可重复的场景时,即视为完成。
由索引模型根据 Issue 内容生成。
描述
PyRIT currently focuses primarily on prompt-level attacks against LLMs, but doesn't include pre-built scenarios for testing RAG-specific vulnerabilities, such as injecting adversarial content into a vector store to manipulate retrieval results (retrieval poisoning). Adding a dedicated test module for simulating poisoned document injection and measuring its effect on generated responses would extend PyRIT's coverage to a growing attack surface as RAG architectures become standard in enterprise AI deployments.
- 主要语言
- Python
- 星标
- 4.5k
- 派生
- 896
- 平均合并
- 3 天 8 小时
- 30 天内合并 PR
- 191
贡献指南
这个仓库没有索引到贡献指南
从这里开始
- 先读完整个 Issue,再读项目的贡献指南。
- 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
- Fork 仓库,在一个分支上完成修改。
- 提交 Pull Request,并在描述里引用这个 Issue 编号。
microsoft/PyRIT 的其他 Issue
-
BUG HarmBench loader drops ContextString, so contextual behaviors are sent without their context 未关闭
难度 2/5 1-3 小时 新手友好度 74/100
-
难度 2/5 1-3 小时 新手友好度 78/100
-
难度 2/5 1-3 小时 新手友好度 82/100
-
难度 2/5 1-3 小时 新手友好度 78/100
-
难度 5/5 一周以上 新手友好度 35/100
相似的 Issue
-
agent-ready documentation needs-triage
难度 1/5 1-3 小时 新手友好度 88/100
-
documentation
难度 1/5 1 小时以内 新手友好度 91/100
-
workflow-status page template still says reusable workflows are "triggered only by workflow_call:" 未关闭
难度 1/5 1 小时以内 新手友好度 92/100
-
instance instance add
难度 1/5 1 小时以内 新手友好度 72/100
searxng/searx-instances#939 · 1 条评论 ·
-
area-deployment area-integrations triage:bot-seen
难度 2/5 半天 新手友好度 86/100