Skip to content

Add AICU - LLM red teaming scanner - #14

Open
Jake-Schoellkopf wants to merge 1 commit into
user1342:mainfrom
Jake-Schoellkopf:add-aicu
Open

Add AICU - LLM red teaming scanner#14
Jake-Schoellkopf wants to merge 1 commit into
user1342:mainfrom
Jake-Schoellkopf:add-aicu

Conversation

@Jake-Schoellkopf

Copy link
Copy Markdown

What is AICU?


│ AICU (https://github.com/Jake-Schoellkopf/aicu) is a black-box LLM security scanner for red teaming LLM applications
and agents.

│ ## Capabilities

│ Attack Suites:
│ - Single-turn prompt injection (173+ payloads)
│ - Multi-turn escalation (crescendo, trust ratcheting, cognitive overload)
│ - Agent/RAG testing (schema extraction, unauthorized tool use, RAG poisoning, tool poisoning, context overflow)
│ - Indirect file injection via multipart uploads
│ - Multimodal attacks: 199 adversarial payloads (LSB steganography, opacity overlays, whisper underlay, frequency
hiding, font remapping, zero-width encoding)

│ Trigger-Sandwich Optimization:
│ All payloads use an adversarial optimization framework (presented at Black Hat USA) that structures inputs to evade
guardrail classifiers:

X_input = X_before ⊕ X_trigger₁ ⊕ X_payload ⊕ X_trigger₂ ⊕ X_after

│ Trigger tokens shift model attention away from safety-checking while making extraction the most probable completion.

│ Iterative Red Teaming: TAP (Tree of Attacks with Pruning), PAIR, and Crescendo algorithms for automated adversarial
optimization

│ 17 Prompt Converters: Composable obfuscation chain (base64, homoglyphs, zero-width, multilingual, etc.)

│ Evaluation: Statistical signals + LLM judge at bug-bounty severity bar + canary detection for ground-truth proof

MIT Licensed | PyPI: pip install aicu-scanner | Docker available

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant