You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
This release prepares evaluator semantics for final-trace verdicts. Until
158
+
that cadence change ships, attack executions still evaluate growing
159
+
prefixes. The attack forms above preserve their intended meaning during
160
+
that transition.
161
+
144
162
### LLMDriver for Adaptive Triggers
145
163
146
164
For multi-turn attacks where the trigger conversation adapts based on agent responses, use [`LLMDriver`][rampart.drivers.llm.LLMDriver] instead of a static string:
@@ -266,6 +268,15 @@ class MyEvaluator(BaseEvaluator):
266
268
267
269
Evaluator tests should cover detection, non-detection, edge cases (empty response, missing data), and that `evidence` / `rationale` are populated correctly.
268
270
271
+
!!! warning "Multi-turn evaluator migration"
272
+
Final-trace verdicts call an evaluator once with the complete transcript.
273
+
A custom evaluator that reads only `context.turns[-1]` intentionally judges
274
+
only the terminal response and cannot preserve earlier evidence. Rewrite
275
+
multi-turn predicates to inspect `context.turns` explicitly before
276
+
migrating execution cadence. The worked execution-strategy loop elsewhere
277
+
on this page still describes the current prefix-evaluation behavior and
278
+
will be replaced with the shared trace runner in the cadence change.
| Existing use | Intended meaning | Explicit form |
140
+
|---|---|---|
141
+
| attack, `ResponseContains(p)`| some turn contains `p`|`ResponseContains(p, scope=ResponseScope.ANY_TURN)`|
142
+
| attack, `~ResponseContains(p)`| some turn does not contain `p`|`~ResponseContains(p, scope=ResponseScope.ALL_TURNS)`|
143
+
| probe, `ResponseContains(p)`| every turn contains `p`|`ResponseContains(p, scope=ResponseScope.ALL_TURNS)`|
144
+
| probe, `~ResponseContains(p)`| no turn contains `p`|`~ResponseContains(p, scope=ResponseScope.ANY_TURN)`|
145
+
146
+
!!! warning "Migration"
147
+
Evaluating an unspecified scope over more than one turn emits a
148
+
`FutureWarning`. Single-turn evaluation is unchanged. Pass
149
+
`ResponseScope.CURRENT_TURN` explicitly when latest-response behavior is
150
+
intentional.
151
+
152
+
This is a preparatory API change. Executions continue to evaluate growing
153
+
prefixes until final-trace verdict cadence ships. In particular, probes
154
+
still stop on the first detected prefix, so `ALL_TURNS` and negated
155
+
`ANY_TURN` cannot yet enforce requirements on prompts that were never
156
+
sent. Choose an explicit scope now so the evaluator's meaning remains
157
+
unambiguous across the migration.
158
+
120
159
### [`SideEffectOccurred`][rampart.evaluators.side_effect.SideEffectOccurred] — Detect Side Effects
121
160
122
161
```python
@@ -172,6 +211,10 @@ judge = LLMJudge(
172
211
)
173
212
```
174
213
214
+
Use `TranscriptScope.FULL` when evidence from any earlier turn must affect the
215
+
final verdict. Under final-trace evaluation, `CURRENT_TURN` intentionally sees
216
+
only the terminal response; it does not preserve evidence from earlier turns.
217
+
175
218
**Custom persona.** The default judge identity is [`NEUTRAL_EVALUATOR`][rampart.evaluators.personas.NEUTRAL_EVALUATOR] — an impartial, literal evaluator. Override it when a different lens is useful:
0 commit comments