Skip to content

FEAT: ImageTechniqueAdaptive Scenario - #3005

Open
Justin Song (jsong468) wants to merge 10 commits into
microsoft:mainfrom
jsong468:image_adaptive_phase_1
Open

Justin Song (jsong468) wants to merge 10 commits into
microsoft:mainfrom
jsong468:image_adaptive_phase_1

Conversation

@jsong468

Copy link
Copy Markdown
Contributor

ImageTechniqueAdaptive: image-rendering adaptive scenario

Description

  • New ImageTechniqueAdaptive scenario (pyrit/scenario/scenarios/adaptive/image_technique_adaptive.py) — an image sibling of TextAdaptive. Renders each text objective into an image payload, sends it to a vision-capable target, and scores the text response using the existing epsilon-greedy adaptive machinery. Rationale: reuses AdaptiveScenario (selector, dispatcher, persistence, resume) unchanged — only the technique pool and target contract differ — so it ships as a thin subclass, not new attack logic. The reason for this name is that the scenario uses image techniques to deliver attacks to the target as opposed to text manipulation techniques like TextAdaptive does and this avoids the confusion of ImageAdaptive that implies that the target is meant to generate images as output. Even a name like ImageInputAdaptive is confusing because that could imply the input objective is image when it is text. A broader rename of TextAdaptive to TextTechniqueAdaptive may be needed in the future that includes targets that take text input and output image.

    • Overrides _get_attack_technique_factories to expose only the image pool, so image techniques never leak into other scenarios' selections.
    • TARGET_REQUIREMENTS requires the target to accept both text and image input and return text. Rationale: image techniques send image-only payloads while the enabled direct-text baseline sends text-only, so both must be accepted for an honest "image vs. text" comparison; incompatible targets are rejected during configuration rather than failing mid-run.
    • Auto-discovered/registered as adaptive.image_technique_adaptive.
  • New source-owned image technique catalog (pyrit/setup/initializers/techniques/image.py) with 6 techniques: blank_canvas, qr_code, grid_composite, scene_background, comic_panel, image_red_teaming. Rationale: kept out of the global core/extra registry and imported directly by the scenario, so a text-only scenario can't select an image technique and fail at runtime against a text-only target. Defaults to the fast single-turn renderings (blank_canvas, grid_composite, comic_panel); qr_code, scene_background, and the slower multi-turn image_red_teaming are opt-in via --techniques.

  • Comic + background assets:

    • Vendored the MIT-licensed ComicJailbreak article.png template (pyrit/datasets/converters/comic_panel/), with LICENSES/ComicJailbreak-MIT.txt and a THIRD_PARTY_NOTICES.txt entry. comic_panel reuses AddImageTextConverter with the template's bounding box — matching how the existing comic_jailbreak dataset already renders comics, so no new converter was needed.
    • Renamed grid_composite/ → innocuous_images/ (lion/roakey/strawberry). Rationale: the photos are shared by both grid_composite and scene_background, so a technique-neutral name is clearer and matches GridCompositeConverter's innocuous_images= parameter.

Tests and Documentation

Tests

  • tests/unit/setup/techniques/test_image_techniques.py — catalog names/shape and that every technique's converter chain terminates in an image_path.
  • tests/unit/scenario/scenarios/adaptive/test_image_technique_adaptive.py — version, baseline policy, target-modality validation (accepts text+image, rejects text-only), image-only factory pool, and default technique set.
  • Updated tests/unit/backend/test_converter_service.py (constructor override for the sequence-typed innocuous_images arg)

Documentation

  • doc/code/scenarios/3_adaptive_scenarios — full ImageTechniqueAdaptive walkthrough (markdown + runnable cell).
  • doc/code/converters/3_image_converters — innocuous_images/ path update

display(image)

# %% [markdown]
# (image-to-image)=

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

nit: delete this?

Image

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I think I would get a build book error when I tried to do this :(

Comment thread doc/code/converters/0_converters.ipynb
@jbolor21

jbolor21 commented Oct 6, 2026 •

Copy link
Copy Markdown
Contributor

design question - should we be able run these image scenarios in a non-adaptive scenario too ie individually? rn if i'm understanding correctly we can ONLY run the image scnearios via the adaptive method? maybe that's outside the scope of "adaptive image scenarios" but i could imagine wanting to only run specific scenarios, not all of them.

@jsong468

Justin Song (jsong468) commented Oct 6, 2026 •

Copy link
Copy Markdown
Contributor Author

design question - should we be able run these image scenarios in a non-adaptive scenario too ie individually? rn if i'm understanding correctly we can ONLY run the image scnearios via the adaptive method? maybe that's outside the scope of "adaptive image scenarios" but i could imagine wanting to only run specific scenarios, not all of them.

this is a good point, and I plan on making a work item to address this more broadly shortly! it will likely either be an image scenario like you said or we can sprinkle them through our existing ones.

@@ -0,0 +1,21 @@
MIT License

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

add to license-files

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

didn't you already add these images ?

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

renamed the directory!

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

although I'll make sure it was actually moved and not copied somehow

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants