English

Insights and Current Gaps in Open-Source LLM Vulnerability Scanners: A Comparative Analysis

Cryptography and Security 2024-11-19 v3 Machine Learning

Abstract

This report presents a comparative analysis of open-source vulnerability scanners for conversational large language models (LLMs). As LLMs become integral to various applications, they also present potential attack surfaces, exposed to security risks such as information leakage and jailbreak attacks. Our study evaluates prominent scanners - Garak, Giskard, PyRIT, and CyberSecEval - that adapt red-teaming practices to expose these vulnerabilities. We detail the distinctive features and practical use of these scanners, outline unifying principles of their design and perform quantitative evaluations to compare them. These evaluations uncover significant reliability issues in detecting successful attacks, highlighting a fundamental gap for future development. Additionally, we contribute a preliminary labelled dataset, which serves as an initial step to bridge this gap. Based on the above, we provide strategic recommendations to assist organizations choose the most suitable scanner for their red-teaming needs, accounting for customizability, test suite comprehensiveness, and industry-specific use cases.

Keywords

Cite

@article{arxiv.2410.16527,
  title  = {Insights and Current Gaps in Open-Source LLM Vulnerability Scanners: A Comparative Analysis},
  author = {Jonathan Brokman and Omer Hofman and Oren Rachmil and Inderjeet Singh and Vikas Pahuja and Rathina Sabapathy Aishvariya Priya and Amit Giloni and Roman Vainshtein and Hisashi Kojima},
  journal= {arXiv preprint arXiv:2410.16527},
  year   = {2024}
}

Comments

15 pages, 11 figures

R2 v1 2026-06-28T19:30:40.407Z