Skip to content

Attacker Modes

Mohammed Danish Amber edited this page Oct 5, 2026 · 1 revision

Attacker Modes

Set with --mode. The attacker turns a scenario's goal into payloads.

seed

Curated payloads from the Seed Payload Library only — no LLM, no API key. Deterministic and reproducible; runs in seconds. Against the bundled The Fixture it proves all 11 scenarios. Ideal for demos and CI.

aphasia run --mode seed

adaptive

An LLM plans every step from the scenario goal and the running history (any model via LLM Providers). Finds novel attacks a fixed corpus would miss; results vary by model strength.

aphasia run --mode adaptive --model gpt-4o-mini

hybrid (default)

Tries the seed payloads first, then lets the LLM adapt on whatever is still unproven. Best of both: reproducible baseline coverage plus novel exploration.

aphasia run --mode hybrid --model gpt-4o-mini

How it works internally

Attacker.next_step(scenario) returns the next seed payload while seeds remain (seed/hybrid), then falls back to provider.plan(...) (adaptive/hybrid), and returns None when seeds are exhausted with no LLM fallback (seed mode) — the run loop ends the scenario. The attacker owns a single history of turns (its deliveries as assistant, target replies as user).

Clone this wiki locally