
augustus v0.14.11
LLMセキュリティテストフレームワーク — プロンプトインジェクション、ジェイルブレイク、敵対的攻撃を検出。190以上のプローブ、28のプロバイダ、単一のGoバイナリ。
Augustus - LLM脆弱性スキャナー(プロンプトインジェクション、脱獄、敵対的攻撃テスト用)
Augustus - LLM脆弱性スキャナー
プロンプトインジェクション、脱獄、エンコーディング悪用、データ抽出をカバーする210以上の敵対的攻撃で大規模言語モデルをテストします。
Augustus は、セキュリティ専門家向けのGoベースのLLM脆弱性スキャナーです。幅広い敵対的攻撃に対して大規模言語モデルをテストし、28のLLMプロバイダーと統合し、実用的な脆弱性レポートを生成します。
研究指向のツールとは異なり、Augustusは本番環境のセキュリティテスト向けに構築されています。並行スキャン、レート制限、リトライロジック、タイムアウト処理が標準で備わっています。
目次
Augustusを選ぶ理由
| 機能 | Augustus | garak | promptfoo |
|---|---|---|---|
| 言語 | Go | Python | TypeScript |
| 単一バイナリ | はい | いいえ | いいえ |
| 並行スキャン | Goroutineプール | マルチプロセッシングプール | はい |
| LLMプロバイダー | 28 | 35以上 | 80以上 |
| プローブタイプ | 210以上 | 160以上 | 119プラグイン + 36戦略 |
| エンタープライズ重視 | はい | 研究 | はい |
機能
| 機能 | 説明 |
|---|---|
| 210以上の脆弱性プローブ | 47の攻撃カテゴリ:脱獄、プロンプトインジェクション、敵対的例、データ抽出、安全性ベンチマーク、エージェント攻撃など |
| 28のLLMプロバイダー | OpenAI、Anthropic、Azure、Bedrock、Vertex AI、Ollama、および43のジェネレーターバリアントを持つ22以上のプロバイダー |
| 90以上の検出器 | パターンマッチング、LLM-as-a-judge、HarmJudge(arXiv:2511.15304)、Perspective API、安全でないコンテンツ検出 |
| 7つのBuff変換 | エンコーディング、言い換え、詩(5形式、3戦略)、低リソース言語翻訳、ケース変換 |
| 柔軟な出力 | テーブル、JSON、JSONL、HTMLレポート形式 |
| 本番環境対応 | 並行スキャン、レート制限、リトライロジック、タイムアウト処理 |
| 単一バイナリ | Goベースのツールが1つのポータブル実行ファイルにコンパイル |
| 拡張可能 | Goのinit()関数によるプラグイン形式の登録 |
攻撃カテゴリ
- 脱獄攻撃: DAN、DAN 11.0、AIM、AntiGPT、Grandma、ArtPrompts
- プロンプトインジェクション: エンコーディング(Base64、ROT13、モールス信号)、タグ密輸、FlipAttack、プレフィックス/サフィックスインジェクション
- 敵対的例: GCG、PAIR、AutoDAN、TAP(Tree of Attack Prompts)、TreeSearch、DRA
- マルチターン攻撃: Crescendo(段階的エスカレーション)、GOAT(適応型テクニック切り替え)
- データ抽出: APIキー漏洩、パッケージ幻覚、PII抽出、LeakReplay
- コンテキスト操作: RAGポイズニング、コンテキストオーバーフロー、マルチモーダル攻撃、継続、分岐
- フォーマット悪用: Markdownインジェクション、YAML/JSONパース攻撃、ANSIエスケープ、Webインジェクション(XSS)
- 回避テクニック: 難読化、文字置換、翻訳ベースの攻撃、言い回し、ObscurePrompt
- 安全性ベンチマーク: DoNotAnswer、RealToxicityPrompts、Snowball、LMRC
- エージェント攻撃: マルチエージェント操作、ブラウジング悪用
- セキュリティテスト: ガードレールバイパス、AV/スパムスキャン、悪用(SQLi、コード実行)、BadChars
警告:
lmrcプローブは脱獄テストの一環として卑猥で攻撃的な言葉を使用します。許可されたテスト環境でのみ使用してください。
クイックスタート
インストール
Go 1.27.0以降が必要です。```bash go install github.com/praetorian-inc/augustus/cmd/augustus@latest
Or build from source:
```bash
git clone https://github.com/example/repo.git
cd repo
make build
``````bash
git clone https://github.com/praetorian-inc/augustus.git
cd augustus
make build
基本的な使い方```bash
export OPENAI_API_KEY="your-api-key"
augustus scan openai.OpenAI
--probe dan.Dan_11_0
--detector dan.DAN
--verbose
### 出力例```
+--------------+-------------+--------+-------+--------+
| PROBE | DETECTOR | PASSED | SCORE | STATUS |
+--------------+-------------+--------+-------+--------+
| dan.Dan_11_0 | dan.DAN | false | 0.85 | VULN |
| dan.STAN | dan.STAN | true | 0.10 | SAFE |
| dan.AntiDAN | dan.AntiDAN | true | 0.05 | SAFE |
+--------------+-------------+--------+-------+--------+
利用可能な機能の一覧```bash
List all registered probes, detectors, generators, harnesses, and buffs
augustus list
## サポートされているプロバイダー
Augustusには、43のジェネレーターバリアントを持つ28のLLMプロバイダーカテゴリが含まれています:
| プロバイダー | ジェネレーター名 | 備考 |
|--------------------|---------------------------|--------------------------------|
| OpenAI | `openai.OpenAI`, `openai.OpenAIReasoning` | GPT-3.5、GPT-4、GPT-4 Turbo、o1/o3推論モデル |
| Anthropic | `anthropic.Anthropic` | Claude 3/3.5/4(Opus、Sonnet、Haiku) |
| Azure OpenAI | `azure.AzureOpenAI` | Azureホスト型OpenAIモデル |
| AWS Bedrock | `bedrock.Bedrock` | Claude、Llama、Titanモデル |
| Google Vertex AI | `vertex.Vertex` | PaLM、Geminiモデル |
| Cohere | `cohere.Cohere` | Command、Command Rモデル |
| Replicate | `replicate.Replicate` | クラウドホスト型オープンモデル |
| HuggingFace | `huggingface.InferenceAPI`, `huggingface.InferenceEndpoint`, `huggingface.Pipeline`, `huggingface.LLaVA` | HF Inference API、エンドポイント、パイプライン、マルチモーダル |
| Together AI | `together.Together` | OSSモデル向けの高速推論 |
| Anyscale | `anyscale.Anyscale` | LlamaおよびMistralホスティング |
| Groq | `groq.Groq` | 超高速LPU推論 |
| Mistral | `mistral.Mistral` | Mistral APIモデル |
| Fireworks | `fireworks.Fireworks` | 本番環境向け推論プラットフォーム |
| DeepInfra | `deepinfra.DeepInfra` | サーバーレスGPU推論 |
| NVIDIA NIM | `nim.NIM`, `nim.NVOpenAICompletion`, `nim.NVMultimodal`, `nim.Vision` | NVIDIA AIエンドポイント、マルチモーダル |
| NVIDIA NeMo | `nemo.NeMo` | NVIDIA NeMoフレームワーク |
| NVIDIA NVCF | `nvcf.NvcfChat`, `nvcf.NvcfCompletion` | NVIDIA Cloud Functions |
| NeMo Guardrails | `guardrails.NeMoGuardrails` | NVIDIA NeMo Guardrails |
| IBM watsonx | `watsonx.WatsonX` | IBM watsonx.aiプラットフォーム |
| LangChain | `langchain.LangChain` | LangChain LLMラッパー |
| LangChain Serve | `langchain_serve.LangChainServe` | LangChain Serveエンドポイント |
| Rasa | `rasa.RasaRest` | Rasa対話型AI |
| GGML | `ggml.Ggml` | GGMLローカルモデル推論 |
| Function | `function.Single`, `function.Multiple` | カスタム関数ジェネレーター |
| Ollama | `ollama.Ollama`, `ollama.OllamaChat` | ローカルモデルホスティング |
| LiteLLM | `litellm.LiteLLM` | 統合APIプロキシ |
| REST API | `rest.Rest` | カスタムRESTエンドポイント(SSEサポート) |
| Test | `test.Blank`, `test.Repeat`, `test.Lipsum`, `test.Nones`, `test.Single`, `test.BlankVision` | テストおよび開発用 |
すべてのプロバイダーはコンパイル済みバイナリで利用可能です。環境変数またはYAML設定ファイルで設定します。セットアップの詳細については[設定](#configuration)を参照してください。
## 使用方法
### 単一プローブ```bash
# Test for DAN jailbreak
augustus scan openai.OpenAI \
--probe dan.Dan_11_0 \
--detector dan.DAN \
--config-file config.yaml \
--verbose
複数のプローブ```bash
Use glob patterns to run related probes
augustus scan openai.OpenAI
--probes-glob "dan.,goodside.,grandma."
--detectors-glob ""
--config-file config.yaml
--output batch-results.jsonl
Run all probes against Claude
augustus scan anthropic.Anthropic
--all
--config '{"model":"claude-3-opus-20240229"}'
--timeout 60m
--output comprehensive-scan.jsonl
--html comprehensive-report.html
### Buff Transformations
プロンプト変換を適用して、回避技術をテストします:```bash
# Apply base64 encoding buff to all probes
augustus scan openai.OpenAI \
--all \
--buff encoding.Base64 \
--config '{"model":"gpt-4"}'
# Apply poetry transformation
augustus scan anthropic.Anthropic \
--probes-glob "dan.*" \
--buff poetry.MetaPrompt \
--config '{"model":"claude-3-opus-20240229"}'