Skip to content

FIX Strip the instruction template from ALERT prompts and keep attack_type - #3019

Merged
Roman Lutz (romanlutz) merged 7 commits into
microsoft:mainfrom
u7k4rs6:fix/alert-instruction-wrapper
Oct 9, 2026
Merged

Roman Lutz (romanlutz) merged 7 commits into
microsoft:mainfrom
u7k4rs6:fix/alert-instruction-wrapper

Conversation

@u7k4rs6

Copy link
Copy Markdown
Contributor

Fixes #3018.

The loader now strips the ### Instruction: / ### Response: template, so the seed is just the prompt. Prompts without the template are left alone. attack_type goes into metadata when the row has it.

Checked on the real HF data: all 45,731 prompts come out unwrapped, and the 30,968 adversarial ones carry attack_type.

Added a test for both (fails on main). tests/unit/datasets: 4958 passed.

@romanlutz Roman Lutz (romanlutz) self-assigned this Oct 9, 2026
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Comment thread pyrit/datasets/seed_datasets/remote/babelscape_alert_dataset.py Outdated
@romanlutz
Roman Lutz (romanlutz) added this pull request to the merge queue Oct 9, 2026
Merged via the queue into microsoft:main with commit 0d07aa3 Oct 9, 2026
55 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

ALERT prompts are sent wrapped in an instruction template

2 participants