FEAT Add Agentic Prompt-Injection Boundary Pairs dataset loader - #2175
FEAT Add Agentic Prompt-Injection Boundary Pairs dataset loader#21753nesdeniz wants to merge 11 commits into
Conversation
…-injection-boundary-dataset # Conflicts: # doc/bibliography.md
…-injection-boundary-dataset
|
This branch is now synchronized with current Fresh validation on the merged head:
The five GitHub Actions runs are currently |
adrian-gavrila
left a comment
There was a problem hiding this comment.
Looks great! Thanks for creating the PR, a couple of small comments and then we should be good to merge.
There was a problem hiding this comment.
Pull request overview
Adds a new remote SeedDatasetProvider loader for the CC BY 4.0 “Agentic Prompt-Injection Boundary Pairs” Hugging Face dataset, integrating it into PyRIT’s dataset discovery and documentation so users can reproducibly load paired prompt-injection boundary cases (attack-only by default, with typed filtering and pair reconstruction support).
Changes:
- Introduces
_AgenticPromptInjectionBoundaryDatasetwith typed enums for label/split/family/source-context filtering, pinned to an immutable HF revision, and with schema + pair-integrity validation. - Registers the loader and enums for discovery via
pyrit.datasets.seed_datasets.remote. - Adds focused unit tests plus documentation/bibliography updates to surface the dataset in the loading guide and citation lists.
Reviewed changes
Copilot reviewed 7 out of 7 changed files in this pull request and generated no comments.
Show a summary per file
| File | Description |
|---|---|
| tests/unit/datasets/test_agentic_prompt_injection_boundary_dataset.py | Adds unit tests covering split loading, label modes, filters, and validation/error cases via mocked HF fetches. |
| pyrit/datasets/seed_datasets/remote/agentic_prompt_injection_boundary_dataset.py | Implements the new remote dataset loader, enums, validation, filtering, and SeedPrompt mapping with pinned HF revision metadata. |
| pyrit/datasets/seed_datasets/remote/init.py | Exports the new loader + enums so they’re discoverable/importable from the remote datasets package. |
| doc/references.bib | Adds the BibTeX citation entry for the dataset. |
| doc/code/datasets/1_loading_datasets.py | Documents the new loader in the dataset loading guide (jupytext source). |
| doc/code/datasets/1_loading_datasets.ipynb | Syncs the executed notebook with the new loader section and updated dataset-name listing output. |
| doc/bibliography.md | Adds the new citation key to the hidden citation-key dropdown list. |
adrian-gavrila
left a comment
There was a problem hiding this comment.
Temporarily revoking approval to do a more thorough review of the dataset itself. Apologies for the confusion.
|
Hi @adrian-gavrila — just checking in so I can track the follow-up correctly. Did the deeper dataset review surface any issues or changes needed on my side? If so, please let me know and I will address them promptly. No rush, and thanks again for taking a closer look. |
|
Thank you for contributing, and I apologize for the slow turnaround on my review. Overall as a dataset loader this PR is good. My hesitation isn't quality, it's provenance. Almost all loaders in PyRIT are backed by a peer-reviewed paper. The few that aren't got there through design discussion with maintainers first. See ATR (#1702 to #1715), where the proposal issue got maintainer direction before the loader was written. #2174 didn't get that engagement, which is my primary concern. Can we take this back to #2174 and have some design discussion? This is also a nascent space in PyRIT and we have to be careful about the datasets that go in to make sure they have a high likelihood of being valuable which brings us back to why most are backed by peer-reviewed papers as those are much more likely to have strong evidence of value. I'm sorry to send you back a step. This is a catalog-direction question that should have |
|
Thanks for the clear explanation, Adrian. I understand the concern, and I agree that the catalog-direction question should have been settled in #2174 before the implementation was built. I'll pause further changes here and continue the design and provenance discussion on the proposal issue. I also appreciate you clarifying that the loader quality itself is not the concern. |
Description
Closes #2174.
This PR adds a remote loader for the public CC BY 4.0 Agentic Prompt-Injection Boundary Pairs dataset:
The loader maps each row to a literal
SeedPromptand pins the immutable v1.0.0 Hugging Face revision. Before filtering, it validates required fields, label-dependent values, allowed families and source contexts, split metadata, duplicate IDs, and complete pair integrity.Family filtering uses
pair_familyso full-pair mode preserves both sides of a controlled pair. Agent-security decision labels and attack families remain in metadata rather than being misclassified as PyRIT harm categories. Pair members remain independent evaluation cases;pair_idpreserves the relationship without collapsing two prompts into oneSeedGroup.Source and release pipeline: https://github.com/3nesdeniz/agentic-prompt-injection-boundary-pairs
I am the dataset author and maintain the tagged source release. The dataset is synthetic, manually reviewed, and contains no customer or private data.
Validation
Revalidated after merging the current upstream
maininto this branch:git diff --checkpassed.The loader is registered in dataset discovery and documented in the loading guide, paired notebook, and project bibliography.