Skip to content

LLM Providers

Mohammed Danish Amber edited this page Oct 5, 2026 · 1 revision

LLM Providers

The adaptive/hybrid attacker uses litellm, so one --model string selects the backend. litellm reads credentials from the provider's usual environment variables.

Model strings

Backend --model example Env var
OpenAI gpt-4o-mini OPENAI_API_KEY
Anthropic anthropic/claude-3-5-haiku ANTHROPIC_API_KEY
Google Gemini gemini/gemini-1.5-flash GEMINI_API_KEY
Groq groq/llama-3.1-8b-instant GROQ_API_KEY
OpenRouter openrouter/<model> OPENROUTER_API_KEY
Ollama (local/remote) ollama/llama3.2:1b — (use --api-base)
vLLM / LM Studio openai/<model> — (use --api-base)

See the litellm provider docs for the full list and exact model names.

--api-base

For self-hosted backends (Ollama, vLLM, LM Studio), pass the server URL:

aphasia run --model ollama/llama3.2:1b --api-base http://host:11434

Default comes from $OLLAMA_API_BASE or $OLLAMA_HOST if set. Unused in seed mode.

No LLM at all

--mode seed needs no provider and no key — see Attacker Modes.

Notes

  • A weak/small model proves fewer scenarios in adaptive mode; the fixture's surfaces are keyword-triggered, so even small models crack several. Use hybrid for reliable coverage.
  • Provider errors (bad key, unreachable host, unserved model) are reported as error verdicts and a non-zero exit — see Troubleshooting.

Clone this wiki locally