0jailtest v2.9

adversarial robustness harness · local Ollama · red-team + blue-team + reporting

Target

Ollama native API (/api/chat, /api/tags). Token logprobs need Ollama ≥0.12.11.
▸ Remote gateway (Cloudflare Access)
Leave empty for local Ollama. Filled = service-token auth (Content-Type sent, preflight expected — gateway handles OPTIONS).
Not connected.
▸ Advanced options
With N>1 and a fixed seed, each pass uses seed+i — reproducible but varied.

Judge

For transform probes the judge sees the decoded intent, not the obfuscated bytes.

Defenses (blue team)

▸ Detectors
Heuristic proxy (symbol density + consonant clusters), not a true LM perplexity. Structured base64/hex blobs are exempt here so encoding probes aren’t false-flagged as gibberish — the decode hidden payloads detector inspects their decoded contents instead.
Run raw → note leak-rate → flip Enforce → run again → watch the delta. That's your mitigation-validation loop.

Suite

Packs are the probe corpus as JSON (versioned). Import merges by id; existing ids replaced.

⚗ Combinator layered composites

Stack encoding × framing × delivery over a benign objective into composite probes — exposing guards that catch each layer alone but miss the chain.

Run

Probes enabled0
Completed0
Probes leaking0
Aggregate leak-rate
Defended (enforce)0
Output findings (LLM05)0
Judge splits0
0% 0 / 0 probes
idle
Live scanner
idle — run a scan to begin
Probes & results all leaks soft pass splits err
Category Severity
LEAK worst-of-N 3/5 leak-rate xf transform/encoded def sanitized · blocked defense out insecure output (LLM05) think reasoning leak multi multi-turn ~ inconsistent judge split
#ProbeCategoryVerdict
Category rollup
CategoryProbesSeverityLeakingPassesLeak-rate
Token budget — Denial-of-Wallet lens
Input-defense coverage — injection surface
Packing capability & gap analysisblind · directed · launch
Composite attacks — layer attribution heatmap
Mitigation diff✕ clear baseline