Skip to article frontmatterSkip to article content
Site not loading correctly?

This may be due to an incorrect BASE_URL configuration. See the MyST Documentation for reference.

Benchmark Scenarios

Benchmark scenarios compare attack effectiveness across an axis that varies within the scenario itself. Currently the only benchmark variant is the adversarial benchmark, whose axis of change is the adversarial chat helper model used in attacks. For full configuration options see pyrit_scan --help and the Scenarios Programming Guide.

Adversarial Benchmark

AdversarialBenchmark holds the objective target and dataset constant and varies the adversarial chat model used to drive multi-turn attacks. Useful for evaluating which adversarial helper models produce stronger or weaker attack success rates against the same target.

Adversarial targets are user-provided via the adversarial_targets scenario parameter. Each name must already be registered in TargetRegistry — typically by TargetInitializer from the ADVERSARIAL_CHAT_* env vars (see .env_example). Use pyrit_scan --list-targets to see every target currently registered.

pyrit_scan benchmark.adversarial \
  --initializers target load_default_datasets \
  --target openai_chat \
  --adversarial-targets adversarial_chat_singleturn adversarial_chat_multiturn \
  --max-dataset-size 4

Pass multiple --adversarial-targets values to compare across models in a single run.

Available strategies: light (default — a quick snapshot using the cheaper techniques), single_turn, multi_turn, plus one member per adversarial-capable source technique (e.g. red_teaming, tap, crescendo_simulated). The light aggregate excludes tap and crescendo_simulated, which can take hours.

Setup