返回更新列表
新发布Jul 27, 2026

augustus v0.14.11

LLM 安全测试框架,用于检测提示注入、越狱和对抗性攻击 — 190+ 探针、28 个提供商、单个 Go 二进制文件

分享

Augustus - 用于提示注入、越狱和对抗性攻击测试的LLM漏洞扫描器

Augustus - LLM漏洞扫描器

针对210多种对抗性攻击测试大型语言模型,涵盖提示注入、越狱、编码利用和数据提取。

CI Go Version License Go Report Card GitHub Release

Augustus 是一款基于Go语言、面向安全专业人员的LLM漏洞扫描器。它针对各种对抗性攻击测试大型语言模型,集成28个LLM提供商,并生成可操作的漏洞报告。

与面向研究的工具不同,Augustus专为生产环境安全测试而构建——并发扫描、速率限制、重试逻辑和超时处理开箱即用。

目录

为什么选择Augustus

功能Augustusgarakpromptfoo
语言GoPythonTypeScript
单一二进制文件是否否
并发扫描Goroutine池多进程池是
LLM提供商2835+80+
探针类型210+160+119个插件 + 36种策略
企业级定位是研究是

功能特性

功能描述
210+漏洞探针47个攻击类别:越狱、提示注入、对抗性示例、数据提取、安全基准、智能体攻击等
28个LLM提供商OpenAI、Anthropic、Azure、Bedrock、Vertex AI、Ollama以及另外22个提供商,共43种生成器变体
90+检测器模式匹配、LLM作为裁判、HarmJudge (arXiv:2511.15304)、Perspective API、不安全内容检测
7种Buff变换编码、改写、诗歌(5种格式、3种策略)、低资源语言翻译、大小写变换
灵活输出表格、JSON、JSONL和HTML报告格式
生产就绪并发扫描、速率限制、重试逻辑、超时处理
单一二进制文件基于Go的工具可编译为单个可移植可执行文件
可扩展通过Go init()函数实现插件式注册

攻击类别

  • 越狱攻击:DAN、DAN 11.0、AIM、AntiGPT、Grandma、ArtPrompts
  • 提示注入:编码(Base64、ROT13、摩尔斯电码)、标签走私、FlipAttack、前缀/后缀注入
  • 对抗性示例:GCG、PAIR、AutoDAN、TAP(攻击提示树)、TreeSearch、DRA
  • 多轮攻击:Crescendo(渐进式升级)、GOAT(自适应技术切换)
  • 数据提取:API密钥泄露、包幻觉、PII提取、LeakReplay
  • 上下文操纵:RAG投毒、上下文溢出、多模态攻击、续写、发散
  • 格式利用:Markdown注入、YAML/JSON解析攻击、ANSI转义、Web注入(XSS)
  • 规避技术:混淆、字符替换、基于翻译的攻击、措辞变换、ObscurePrompt
  • 安全基准:DoNotAnswer、RealToxicityPrompts、Snowball、LMRC
  • 智能体攻击:多智能体操纵、浏览利用
  • 安全测试:护栏绕过、AV/垃圾邮件扫描、利用(SQLi、代码执行)、BadChars

警告:lmrc探针在越狱测试中使用粗俗和冒犯性语言。请仅在授权的测试环境中使用。

快速开始

安装

需要Go 1.27.0或更高版本。```bash go install github.com/praetorian-inc/augustus/cmd/augustus@latest

或者从源码构建:```bash
git clone https://github.com/praetorian-inc/augustus.git
cd augustus
make build

基本用法```bash

export OPENAI_API_KEY="your-api-key" augustus scan openai.OpenAI
--probe dan.Dan_11_0
--detector dan.DAN
--verbose

### 示例输出```
+--------------+-------------+--------+-------+--------+
| PROBE        | DETECTOR    | PASSED | SCORE | STATUS |
+--------------+-------------+--------+-------+--------+
| dan.Dan_11_0 | dan.DAN     | false  | 0.85  | VULN   |
| dan.STAN     | dan.STAN    | true   | 0.10  | SAFE   |
| dan.AntiDAN  | dan.AntiDAN | true   | 0.05  | SAFE   |
+--------------+-------------+--------+-------+--------+

列出可用功能```bash

List all registered probes, detectors, generators, harnesses, and buffs

augustus list

## 支持的提供商

Augustus 包含 28 个 LLM 提供商类别,共 43 个生成器变体:

| 提供商             | 生成器名称                | 说明                            |
|--------------------|---------------------------|--------------------------------|
| OpenAI             | `openai.OpenAI`, `openai.OpenAIReasoning` | GPT-3.5、GPT-4、GPT-4 Turbo、o1/o3 推理模型 |
| Anthropic          | `anthropic.Anthropic`     | Claude 3/3.5/4(Opus、Sonnet、Haiku) |
| Azure OpenAI       | `azure.AzureOpenAI`       | Azure 托管的 OpenAI 模型        |
| AWS Bedrock        | `bedrock.Bedrock`         | Claude、Llama、Titan 模型       |
| Google Vertex AI   | `vertex.Vertex`           | PaLM、Gemini 模型               |
| Cohere             | `cohere.Cohere`           | Command、Command R 模型         |
| Replicate          | `replicate.Replicate`     | 云端托管的开源模型              |
| HuggingFace        | `huggingface.InferenceAPI`, `huggingface.InferenceEndpoint`, `huggingface.Pipeline`, `huggingface.LLaVA` | HF 推理 API、端点、流水线、多模态 |
| Together AI        | `together.Together`       | 面向 OSS 模型的快速推理         |
| Anyscale           | `anyscale.Anyscale`       | Llama 和 Mistral 托管           |
| Groq               | `groq.Groq`               | 超快 LPU 推理                   |
| Mistral            | `mistral.Mistral`         | Mistral API 模型                |
| Fireworks          | `fireworks.Fireworks`     | 生产级推理平台                  |
| DeepInfra          | `deepinfra.DeepInfra`     | 无服务器 GPU 推理               |
| NVIDIA NIM         | `nim.NIM`, `nim.NVOpenAICompletion`, `nim.NVMultimodal`, `nim.Vision` | NVIDIA AI 端点、多模态 |
| NVIDIA NeMo        | `nemo.NeMo`               | NVIDIA NeMo 框架                |
| NVIDIA NVCF        | `nvcf.NvcfChat`, `nvcf.NvcfCompletion` | NVIDIA 云函数          |
| NeMo Guardrails    | `guardrails.NeMoGuardrails` | NVIDIA NeMo Guardrails        |
| IBM watsonx        | `watsonx.WatsonX`         | IBM watsonx.ai 平台             |
| LangChain          | `langchain.LangChain`     | LangChain LLM 封装器            |
| LangChain Serve    | `langchain_serve.LangChainServe` | LangChain Serve 端点    |
| Rasa               | `rasa.RasaRest`           | Rasa 对话式 AI                  |
| GGML               | `ggml.Ggml`               | GGML 本地模型推理               |
| Function           | `function.Single`, `function.Multiple` | 自定义函数生成器      |
| Ollama             | `ollama.Ollama`, `ollama.OllamaChat` | 本地模型托管         |
| LiteLLM            | `litellm.LiteLLM`         | 统一 API 代理                   |
| REST API           | `rest.Rest`               | 自定义 REST 端点(支持 SSE)    |
| Test               | `test.Blank`, `test.Repeat`, `test.Lipsum`, `test.Nones`, `test.Single`, `test.BlankVision` | 测试与开发 |

所有提供商均可在编译后的二进制文件中使用。可通过环境变量或 YAML 配置文件进行配置。有关设置详情,请参阅[配置](#configuration)。

## 使用方法

### 单次探测```bash
# Test for DAN jailbreak
augustus scan openai.OpenAI \
  --probe dan.Dan_11_0 \
  --detector dan.DAN \
  --config-file config.yaml \
  --verbose

多探针```bash

Use glob patterns to run related probes

augustus scan openai.OpenAI
--probes-glob "dan.,goodside.,grandma."
--detectors-glob "
"
--config-file config.yaml
--output batch-results.jsonl

Run all probes against Claude

augustus scan anthropic.Anthropic
--all
--config '{"model":"claude-3-opus-20240229"}'
--timeout 60m
--output comprehensive-scan.jsonl
--html comprehensive-report.html

### Buff 变换

应用提示变换来测试规避技术:```bash
# Apply base64 encoding buff to all probes
augustus scan openai.OpenAI \
  --all \
  --buff encoding.Base64 \
  --config '{"model":"gpt-4"}'

# Apply poetry transformation
augustus scan anthropic.Anthropic \
  --probes-glob "dan.*" \
  --buff poetry.MetaPrompt \
  --config '{"model":"claude-3-opus-20240229"}'

# Chain multiple buffs
augustus scan openai.OpenAI \
  --all \
  --buffs-glob "encoding.*,paraphrase.*" \
  --output buffed-results.jsonl

输出格式```bash

Table format (default) - human-readable

augustus scan openai.OpenAI --probe dan.Dan_11_0 --format table

JSON format - structured output

augustus scan openai.OpenAI --probe dan.Dan_11_0 --format json

JSONL format - one JSON object per line, ideal for piping

augustus scan openai.OpenAI --probe dan.Dan_11_0 --format jsonl

分类