
augustus v0.14.11
LLM 安全测试框架,用于检测提示注入、越狱和对抗性攻击 — 190+ 探针、28 个提供商、单个 Go 二进制文件
Augustus - 用于提示注入、越狱和对抗性攻击测试的LLM漏洞扫描器
Augustus - LLM漏洞扫描器
针对210多种对抗性攻击测试大型语言模型,涵盖提示注入、越狱、编码利用和数据提取。
Augustus 是一款基于Go语言、面向安全专业人员的LLM漏洞扫描器。它针对各种对抗性攻击测试大型语言模型,集成28个LLM提供商,并生成可操作的漏洞报告。
与面向研究的工具不同,Augustus专为生产环境安全测试而构建——并发扫描、速率限制、重试逻辑和超时处理开箱即用。
目录
为什么选择Augustus
| 功能 | Augustus | garak | promptfoo |
|---|---|---|---|
| 语言 | Go | Python | TypeScript |
| 单一二进制文件 | 是 | 否 | 否 |
| 并发扫描 | Goroutine池 | 多进程池 | 是 |
| LLM提供商 | 28 | 35+ | 80+ |
| 探针类型 | 210+ | 160+ | 119个插件 + 36种策略 |
| 企业级定位 | 是 | 研究 | 是 |
功能特性
| 功能 | 描述 |
|---|---|
| 210+漏洞探针 | 47个攻击类别:越狱、提示注入、对抗性示例、数据提取、安全基准、智能体攻击等 |
| 28个LLM提供商 | OpenAI、Anthropic、Azure、Bedrock、Vertex AI、Ollama以及另外22个提供商,共43种生成器变体 |
| 90+检测器 | 模式匹配、LLM作为裁判、HarmJudge (arXiv:2511.15304)、Perspective API、不安全内容检测 |
| 7种Buff变换 | 编码、改写、诗歌(5种格式、3种策略)、低资源语言翻译、大小写变换 |
| 灵活输出 | 表格、JSON、JSONL和HTML报告格式 |
| 生产就绪 | 并发扫描、速率限制、重试逻辑、超时处理 |
| 单一二进制文件 | 基于Go的工具可编译为单个可移植可执行文件 |
| 可扩展 | 通过Go init()函数实现插件式注册 |
攻击类别
- 越狱攻击:DAN、DAN 11.0、AIM、AntiGPT、Grandma、ArtPrompts
- 提示注入:编码(Base64、ROT13、摩尔斯电码)、标签走私、FlipAttack、前缀/后缀注入
- 对抗性示例:GCG、PAIR、AutoDAN、TAP(攻击提示树)、TreeSearch、DRA
- 多轮攻击:Crescendo(渐进式升级)、GOAT(自适应技术切换)
- 数据提取:API密钥泄露、包幻觉、PII提取、LeakReplay
- 上下文操纵:RAG投毒、上下文溢出、多模态攻击、续写、发散
- 格式利用:Markdown注入、YAML/JSON解析攻击、ANSI转义、Web注入(XSS)
- 规避技术:混淆、字符替换、基于翻译的攻击、措辞变换、ObscurePrompt
- 安全基准:DoNotAnswer、RealToxicityPrompts、Snowball、LMRC
- 智能体攻击:多智能体操纵、浏览利用
- 安全测试:护栏绕过、AV/垃圾邮件扫描、利用(SQLi、代码执行)、BadChars
警告:
lmrc探针在越狱测试中使用粗俗和冒犯性语言。请仅在授权的测试环境中使用。
快速开始
安装
需要Go 1.27.0或更高版本。```bash go install github.com/praetorian-inc/augustus/cmd/augustus@latest
或者从源码构建:```bash
git clone https://github.com/praetorian-inc/augustus.git
cd augustus
make build
基本用法```bash
export OPENAI_API_KEY="your-api-key"
augustus scan openai.OpenAI
--probe dan.Dan_11_0
--detector dan.DAN
--verbose
### 示例输出```
+--------------+-------------+--------+-------+--------+
| PROBE | DETECTOR | PASSED | SCORE | STATUS |
+--------------+-------------+--------+-------+--------+
| dan.Dan_11_0 | dan.DAN | false | 0.85 | VULN |
| dan.STAN | dan.STAN | true | 0.10 | SAFE |
| dan.AntiDAN | dan.AntiDAN | true | 0.05 | SAFE |
+--------------+-------------+--------+-------+--------+
列出可用功能```bash
List all registered probes, detectors, generators, harnesses, and buffs
augustus list
## 支持的提供商
Augustus 包含 28 个 LLM 提供商类别,共 43 个生成器变体:
| 提供商 | 生成器名称 | 说明 |
|--------------------|---------------------------|--------------------------------|
| OpenAI | `openai.OpenAI`, `openai.OpenAIReasoning` | GPT-3.5、GPT-4、GPT-4 Turbo、o1/o3 推理模型 |
| Anthropic | `anthropic.Anthropic` | Claude 3/3.5/4(Opus、Sonnet、Haiku) |
| Azure OpenAI | `azure.AzureOpenAI` | Azure 托管的 OpenAI 模型 |
| AWS Bedrock | `bedrock.Bedrock` | Claude、Llama、Titan 模型 |
| Google Vertex AI | `vertex.Vertex` | PaLM、Gemini 模型 |
| Cohere | `cohere.Cohere` | Command、Command R 模型 |
| Replicate | `replicate.Replicate` | 云端托管的开源模型 |
| HuggingFace | `huggingface.InferenceAPI`, `huggingface.InferenceEndpoint`, `huggingface.Pipeline`, `huggingface.LLaVA` | HF 推理 API、端点、流水线、多模态 |
| Together AI | `together.Together` | 面向 OSS 模型的快速推理 |
| Anyscale | `anyscale.Anyscale` | Llama 和 Mistral 托管 |
| Groq | `groq.Groq` | 超快 LPU 推理 |
| Mistral | `mistral.Mistral` | Mistral API 模型 |
| Fireworks | `fireworks.Fireworks` | 生产级推理平台 |
| DeepInfra | `deepinfra.DeepInfra` | 无服务器 GPU 推理 |
| NVIDIA NIM | `nim.NIM`, `nim.NVOpenAICompletion`, `nim.NVMultimodal`, `nim.Vision` | NVIDIA AI 端点、多模态 |
| NVIDIA NeMo | `nemo.NeMo` | NVIDIA NeMo 框架 |
| NVIDIA NVCF | `nvcf.NvcfChat`, `nvcf.NvcfCompletion` | NVIDIA 云函数 |
| NeMo Guardrails | `guardrails.NeMoGuardrails` | NVIDIA NeMo Guardrails |
| IBM watsonx | `watsonx.WatsonX` | IBM watsonx.ai 平台 |
| LangChain | `langchain.LangChain` | LangChain LLM 封装器 |
| LangChain Serve | `langchain_serve.LangChainServe` | LangChain Serve 端点 |
| Rasa | `rasa.RasaRest` | Rasa 对话式 AI |
| GGML | `ggml.Ggml` | GGML 本地模型推理 |
| Function | `function.Single`, `function.Multiple` | 自定义函数生成器 |
| Ollama | `ollama.Ollama`, `ollama.OllamaChat` | 本地模型托管 |
| LiteLLM | `litellm.LiteLLM` | 统一 API 代理 |
| REST API | `rest.Rest` | 自定义 REST 端点(支持 SSE) |
| Test | `test.Blank`, `test.Repeat`, `test.Lipsum`, `test.Nones`, `test.Single`, `test.BlankVision` | 测试与开发 |
所有提供商均可在编译后的二进制文件中使用。可通过环境变量或 YAML 配置文件进行配置。有关设置详情,请参阅[配置](#configuration)。
## 使用方法
### 单次探测```bash
# Test for DAN jailbreak
augustus scan openai.OpenAI \
--probe dan.Dan_11_0 \
--detector dan.DAN \
--config-file config.yaml \
--verbose
多探针```bash
Use glob patterns to run related probes
augustus scan openai.OpenAI
--probes-glob "dan.,goodside.,grandma."
--detectors-glob ""
--config-file config.yaml
--output batch-results.jsonl
Run all probes against Claude
augustus scan anthropic.Anthropic
--all
--config '{"model":"claude-3-opus-20240229"}'
--timeout 60m
--output comprehensive-scan.jsonl
--html comprehensive-report.html
### Buff 变换
应用提示变换来测试规避技术:```bash
# Apply base64 encoding buff to all probes
augustus scan openai.OpenAI \
--all \
--buff encoding.Base64 \
--config '{"model":"gpt-4"}'
# Apply poetry transformation
augustus scan anthropic.Anthropic \
--probes-glob "dan.*" \
--buff poetry.MetaPrompt \
--config '{"model":"claude-3-opus-20240229"}'
# Chain multiple buffs
augustus scan openai.OpenAI \
--all \
--buffs-glob "encoding.*,paraphrase.*" \
--output buffed-results.jsonl
输出格式```bash
Table format (default) - human-readable
augustus scan openai.OpenAI --probe dan.Dan_11_0 --format table
JSON format - structured output
augustus scan openai.OpenAI --probe dan.Dan_11_0 --format json
JSONL format - one JSON object per line, ideal for piping
augustus scan openai.OpenAI --probe dan.Dan_11_0 --format jsonl