-
Notifications
You must be signed in to change notification settings - Fork 0
LLM Providers
Mohammed Danish Amber edited this page Oct 5, 2026
·
1 revision
The adaptive/hybrid attacker uses litellm, so one
--model string selects the backend. litellm reads credentials from the provider's usual
environment variables.
| Backend |
--model example |
Env var |
|---|---|---|
| OpenAI | gpt-4o-mini |
OPENAI_API_KEY |
| Anthropic | anthropic/claude-3-5-haiku |
ANTHROPIC_API_KEY |
| Google Gemini | gemini/gemini-1.5-flash |
GEMINI_API_KEY |
| Groq | groq/llama-3.1-8b-instant |
GROQ_API_KEY |
| OpenRouter | openrouter/<model> |
OPENROUTER_API_KEY |
| Ollama (local/remote) | ollama/llama3.2:1b |
— (use --api-base) |
| vLLM / LM Studio | openai/<model> |
— (use --api-base) |
See the litellm provider docs for the full list and exact model names.
For self-hosted backends (Ollama, vLLM, LM Studio), pass the server URL:
aphasia run --model ollama/llama3.2:1b --api-base http://host:11434
Default comes from $OLLAMA_API_BASE or $OLLAMA_HOST if set. Unused in seed mode.
--mode seed needs no provider and no key — see Attacker Modes.
- A weak/small model proves fewer scenarios in
adaptivemode; the fixture's surfaces are keyword-triggered, so even small models crack several. Usehybridfor reliable coverage. - Provider errors (bad key, unreachable host, unserved model) are reported as
errorverdicts and a non-zero exit — see Troubleshooting.