Skip to content

FEAT: Attack analytics SDK - #3059

Merged
Roman Lutz (romanlutz) merged 13 commits into
microsoft:mainfrom
romanlutz:romanlutz-sdk-attack-analytics
Oct 11, 2026
Merged

Roman Lutz (romanlutz) merged 13 commits into
microsoft:mainfrom
romanlutz:romanlutz-sdk-attack-analytics

Conversation

@romanlutz

Copy link
Copy Markdown
Contributor

Description

Part 3 of the CoPyRIT attack-results analytics roadmap, following the merged contracts (#2742) and storage (#2792). This makes saved-result analytics available to Python callers without introducing analytics REST endpoints or the GUI explorer.

  • Add async AttackResultAnalytics.query_async, results_async, and facets_async, plus close_async and an async context manager. Reports include a coherent initial lightweight result page; subsequent pages and facets do not recalculate reports or hydrate conversations, scores, or media.
  • Share one loop-bound controller per memory object, with separate report and quick-query capacity. Defaults are five report slots, two page/facet slots, ten queued calls per lane, a one-second queue wait, and five-/one-second execution budgets. Cancellation and response expiry retain capacity until the actual operation/session cleanup finishes. Shutdown drains before another controller can replace it. These are overload safeguards, not latency guarantees.
  • Aggregate reader-approved SQLite profiles with Unicode str.lower semantics, deduplicated memberships, typed missing/no-converter values, stable labels, and parity with the complete SQL fallback. Overflow falls back without sampling or partial totals. Exact appended drill-down predicates preserve existing filters and the 16-predicate/500-value budget.
  • Consolidate attack and scenario calculations in compute_outcome_statistics / combine_outcome_statistics. Both expose decided-only success_rate_decided and all-outcome success_rate_all; success_rate remains compatible. Raw analytics still counts every saved result ID, while scenario statistics still selects the latest attempt per execution unit. Historical retry/error counts remain separate from selected outcome counts.
  • Reject contradictory rich statistics and revalidate mutable inputs before combining them. Add include_outcome_statistics=True to the maintained analyze_results and compute_technique_stats_async APIs while retaining the original six-field AttackStats defaults. Scenario progress and JSON output carry the shared statistics; existing displayed percentages and deprecation schedules remain unchanged.

The shared-calculation follow-up builds on #2820 and preserves the explicit result roles from #2997 without silently excluding any role. Existing lazy exports and import boundaries are retained. Requests are snapshotted and revalidated before admission. There is no persistent result cache or in-flight coalescing.

No schema/migration changes, shared/live database access, History selection changes, new endpoints, frontend changes, or backend lifecycle wiring. REST/History integration, the HTTP performance gate, and the explorer remain roadmap parts 4 and 5. The profile caps bound transferred profiles and SDK work, not SQL scans or peak network bytes.

Tests and Documentation

Added SDK, execution-lifetime, SQL/profile parity, shared-outcome, consistency/serialization, and compatibility coverage. Regressions include all outcomes and empty denominators, exact drill-down boundaries, Unicode and legacy converter metadata, profile caps/overflow, request snapshots, independent native async sessions, task-start failures, Python 3.11 admission-cancellation races, and deterministic shutdown. Scenario/backend/JSON parity and maintained-versus-deprecated API behavior are also covered.

Updated the Python analytics guide, framework responsibilities, and documentation navigation. The guide explains both denominator policies, resource ownership, compatibility, and the limitations of the bounded profile path.

Current head, Windows / Python 3.14.4:

uv run --no-sync pytest -q -n 4 --dist=loadfile tests\unit\analytics tests\unit\models\test_analytics.py tests\unit\models\test_scenario_progress.py tests\unit\models\test_import_boundary.py tests\unit\output\scenario_result tests\unit\output\test_derivation.py --timeout=90

Result: 620 passed.

  • uv run --no-sync ty check pyrit: passed.
  • uv run --no-sync python -m build_scripts.validate_docs: passed, including 165 navigation references and the orphaned-file check.
  • git --no-pager diff --check: passed.
  • All applicable normal commit hooks passed, including Ruff formatting/lint, async naming, documentation, and typing. No hooks were skipped.
Additional cross-version and broader compatibility evidence

Python 3.11.15, using a temporary uv-managed environment inside this worktree:

$env:UV_PROJECT_ENVIRONMENT = '.venv-py311'
uv run --no-sync --python 3.11 pytest -q tests\unit\models\test_analytics.py tests\unit\analytics\test_outcome_statistics.py tests\unit\analytics\test_scenario_statistics.py tests\unit\analytics\test_result_analysis.py tests\unit\analytics\test_technique_analysis.py tests\unit\analytics\test_attack_result_analytics.py tests\unit\analytics\test_scenario_statistics_parity.py tests\unit\output\scenario_result\test_json.py --timeout=90

Result: 369 passed, with an existing third-party confusables invalid-escape warning. The temporary environment was removed afterward.

The broader Python 3.14.4 compatibility run included scenario services/routes, adaptive selectors, output formats, and lazy imports:

uv run --no-sync pytest -q -n 4 --dist=loadfile tests\unit\analytics tests\unit\models\test_analytics.py tests\unit\models\test_scenario_progress.py tests\unit\models\test_scenario_result.py tests\unit\models\test_import_boundary.py tests\unit\output\test_derivation.py tests\unit\output\scenario_result tests\unit\backend\test_scenario_progress_read_model.py tests\unit\backend\test_scenario_run_service.py tests\unit\backend\test_scenario_run_routes.py tests\unit\common\test_lazy_package_imports.py tests\unit\scenario\scenarios\adaptive\test_epsilon_greedy.py --timeout=90

Result: 1,062 passed; one scenario alias-import subprocess hit its existing 30-second timeout. That unchanged test and the new technique lazy-export test both passed in isolation:

uv run --no-sync pytest -q tests\unit\common\test_lazy_package_imports.py::test_scenario_short_imports_preserve_canonical_identity 'tests\unit\common\test_lazy_package_imports.py::test_lazy_import_spot_check[pyrit.analytics0]' --timeout=90

Result: 2 passed in 9.31 seconds. No test timeout or import guard was weakened.

Full-repository, live Azure SQL, and HTTP/100,000-row performance validation were not run. SQLite coverage uses isolated test databases. Weighted SDK profile coverage is not a production latency claim.

JupyText was not run: this changeset adds Markdown documentation, not paired Python/notebook examples.

Roman Lutz (romanlutz) and others added 7 commits October 8, 2026 00:21
Interpret saved outcome counts through an async SDK with shared loop-bound admission, cooperative cancellation, and deterministic cleanup. Match bounded Unicode profile aggregation to the complete SQL fallback, with exact drilldowns, focused compatibility coverage, and SDK lifecycle documentation.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Preserve cancellation when admission races with a slot grant on Python 3.11. Release unscheduled operation capacity and close rejected coroutines, keep shutdown retryable, and log failures that race with caller cancellation. Add deterministic lifecycle regressions and verify raw-result analytics remains distinct from scenario-unit statistics and explicit result-role policy.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Expose decided-only and all-outcome success rates through one calculator and shared model. Keep raw saved-result selection distinct from scenario latest-unit selection while reusing count validation, rates, shares, and percentage formatting. Preserve legacy defaults and carry both rates through scenario progress and JSON projections.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Reject contradictory scenario totals and outcome breakdowns, including mutated inputs at aggregation boundaries. Expose an explicit read-only success_rate_decided alias in shared statistics and JSON. Add typed include_outcome_statistics opt-ins to maintained result and async technique analytics while preserving the six-field default and existing deprecation schedules.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
@romanlutz
Roman Lutz (romanlutz) added this pull request to the merge queue Oct 11, 2026
@github-merge-queue
github-merge-queue Bot removed this pull request from the merge queue due to failed status checks Oct 11, 2026
@romanlutz
Roman Lutz (romanlutz) added this pull request to the merge queue Oct 11, 2026
@github-merge-queue
github-merge-queue Bot removed this pull request from the merge queue due to failed status checks Oct 11, 2026
@romanlutz
Roman Lutz (romanlutz) added this pull request to the merge queue Oct 11, 2026
@github-merge-queue
github-merge-queue Bot removed this pull request from the merge queue due to failed status checks Oct 11, 2026
@romanlutz
Roman Lutz (romanlutz) added this pull request to the merge queue Oct 11, 2026
@github-merge-queue
github-merge-queue Bot removed this pull request from the merge queue due to failed status checks Oct 11, 2026
@romanlutz
Roman Lutz (romanlutz) added this pull request to the merge queue Oct 11, 2026
@github-merge-queue
github-merge-queue Bot removed this pull request from the merge queue due to failed status checks Oct 11, 2026
@romanlutz
Roman Lutz (romanlutz) added this pull request to the merge queue Oct 11, 2026
@github-merge-queue
github-merge-queue Bot removed this pull request from the merge queue due to failed status checks Oct 11, 2026
@romanlutz
Roman Lutz (romanlutz) added this pull request to the merge queue Oct 11, 2026
@github-merge-queue
github-merge-queue Bot removed this pull request from the merge queue due to failed status checks Oct 11, 2026
@romanlutz
Roman Lutz (romanlutz) added this pull request to the merge queue Oct 11, 2026
@github-merge-queue
github-merge-queue Bot removed this pull request from the merge queue due to failed status checks Oct 11, 2026
@romanlutz
Roman Lutz (romanlutz) added this pull request to the merge queue Oct 11, 2026
@github-merge-queue
github-merge-queue Bot removed this pull request from the merge queue due to failed status checks Oct 11, 2026
@romanlutz
Roman Lutz (romanlutz) added this pull request to the merge queue Oct 11, 2026
@github-merge-queue
github-merge-queue Bot removed this pull request from the merge queue due to failed status checks Oct 11, 2026
@romanlutz
Roman Lutz (romanlutz) added this pull request to the merge queue Oct 11, 2026
@github-merge-queue
github-merge-queue Bot removed this pull request from the merge queue due to failed status checks Oct 11, 2026
@romanlutz
Roman Lutz (romanlutz) added this pull request to the merge queue Oct 11, 2026
@github-merge-queue
github-merge-queue Bot removed this pull request from the merge queue due to failed status checks Oct 11, 2026
@romanlutz
Roman Lutz (romanlutz) added this pull request to the merge queue Oct 11, 2026
@github-merge-queue
github-merge-queue Bot removed this pull request from the merge queue due to failed status checks Oct 11, 2026
@romanlutz
Roman Lutz (romanlutz) added this pull request to the merge queue Oct 11, 2026
@github-merge-queue
github-merge-queue Bot removed this pull request from the merge queue due to failed status checks Oct 11, 2026
@romanlutz
Roman Lutz (romanlutz) added this pull request to the merge queue Oct 11, 2026
@github-merge-queue
github-merge-queue Bot removed this pull request from the merge queue due to failed status checks Oct 11, 2026
@romanlutz
Roman Lutz (romanlutz) added this pull request to the merge queue Oct 11, 2026
@github-merge-queue
github-merge-queue Bot removed this pull request from the merge queue due to failed status checks Oct 11, 2026
Use explicit finite test budgets for native SQLite semantic checks instead of requiring loaded CI runners to meet the SDK's one-second quick-query safeguard. Preserve admission capacities, production deadlines, and every semantic assertion. Add event-driven tests of the unchanged default execution budgets and capacity retention through timeout cleanup.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Update the required base to 1ba8bcd while preserving the analytics SDK and deterministic CI regression fix.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Include the decoding scorer identity and opt-in WebSocket tracing base updates that landed during validation.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Update the required base to dc8510a while preserving the analytics SDK and deterministic deadline tests.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Include upstream SDK test isolation and plagiarism normalization through 0a5abbf, preserving the analytics changes.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Update the required base to 1bf811f while preserving the analytics changes and deterministic deadline tests.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
@romanlutz
Roman Lutz (romanlutz) added this pull request to the merge queue Oct 11, 2026
Merged via the queue into microsoft:main with commit 5c3cf08 Oct 11, 2026
55 checks passed
@romanlutz
Roman Lutz (romanlutz) deleted the romanlutz-sdk-attack-analytics branch October 11, 2026 16:46
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants