Repository navigation
FEAT: ImageTechniqueAdaptive Scenario - #3005
Justin Song (jsong468) wants to merge 10 commits into
Conversation
| display(image) | ||
|
|
||
| # %% [markdown] | ||
| # (image-to-image)= |
There was a problem hiding this comment.
I think I would get a build book error when I tried to do this :(
|
design question - should we be able run these image scenarios in a non-adaptive scenario too ie individually? rn if i'm understanding correctly we can ONLY run the image scnearios via the adaptive method? maybe that's outside the scope of "adaptive image scenarios" but i could imagine wanting to only run specific scenarios, not all of them. |
this is a good point, and I plan on making a work item to address this more broadly shortly! it will likely either be an image scenario like you said or we can sprinkle them through our existing ones. |
| @@ -0,0 +1,21 @@ | |||
| MIT License | |||
There was a problem hiding this comment.
add to license-files
There was a problem hiding this comment.
didn't you already add these images ?
There was a problem hiding this comment.
renamed the directory!
There was a problem hiding this comment.
although I'll make sure it was actually moved and not copied somehow

ImageTechniqueAdaptive: image-rendering adaptive scenario
Description
New
ImageTechniqueAdaptivescenario (pyrit/scenario/scenarios/adaptive/image_technique_adaptive.py) — an image sibling ofTextAdaptive. Renders each text objective into an image payload, sends it to a vision-capable target, and scores the text response using the existing epsilon-greedy adaptive machinery. Rationale: reusesAdaptiveScenario(selector, dispatcher, persistence, resume) unchanged — only the technique pool and target contract differ — so it ships as a thin subclass, not new attack logic. The reason for this name is that the scenario uses image techniques to deliver attacks to the target as opposed to text manipulation techniques likeTextAdaptivedoes and this avoids the confusion ofImageAdaptivethat implies that the target is meant to generate images as output. Even a name likeImageInputAdaptiveis confusing because that could imply the input objective is image when it is text. A broader rename ofTextAdaptivetoTextTechniqueAdaptivemay be needed in the future that includes targets that take text input and output image._get_attack_technique_factoriesto expose only the image pool, so image techniques never leak into other scenarios' selections.TARGET_REQUIREMENTSrequires the target to accept both text and image input and return text. Rationale: image techniques send image-only payloads while the enabled direct-text baseline sends text-only, so both must be accepted for an honest "image vs. text" comparison; incompatible targets are rejected during configuration rather than failing mid-run.adaptive.image_technique_adaptive.New source-owned image technique catalog (
pyrit/setup/initializers/techniques/image.py) with 6 techniques:blank_canvas,qr_code,grid_composite,scene_background,comic_panel,image_red_teaming. Rationale: kept out of the globalcore/extraregistry and imported directly by the scenario, so a text-only scenario can't select an image technique and fail at runtime against a text-only target. Defaults to the fast single-turn renderings (blank_canvas,grid_composite,comic_panel);qr_code,scene_background, and the slower multi-turnimage_red_teamingare opt-in via--techniques.Comic + background assets:
article.pngtemplate (pyrit/datasets/converters/comic_panel/), withLICENSES/ComicJailbreak-MIT.txtand aTHIRD_PARTY_NOTICES.txtentry.comic_panelreusesAddImageTextConverterwith the template's bounding box — matching how the existingcomic_jailbreakdataset already renders comics, so no new converter was needed.grid_composite/→innocuous_images/(lion/roakey/strawberry). Rationale: the photos are shared by bothgrid_compositeandscene_background, so a technique-neutral name is clearer and matchesGridCompositeConverter'sinnocuous_images=parameter.Tests and Documentation
Tests
tests/unit/setup/techniques/test_image_techniques.py— catalog names/shape and that every technique's converter chain terminates in animage_path.tests/unit/scenario/scenarios/adaptive/test_image_technique_adaptive.py— version, baseline policy, target-modality validation (accepts text+image, rejects text-only), image-only factory pool, and default technique set.tests/unit/backend/test_converter_service.py(constructor override for the sequence-typedinnocuous_imagesarg)Documentation
doc/code/scenarios/3_adaptive_scenarios— fullImageTechniqueAdaptivewalkthrough (markdown + runnable cell).doc/code/converters/3_image_converters—innocuous_images/path update