Module 03
BFS engine
Catalogued attacks find what is already known. Against a hardened model, what penetrates is usually the combination of two techniques that fail on their own. The BFS engine explores that combinatorial space in a directed way rather than blindly.
The combination space cannot be walked by hand
With ten categories, dozens of techniques per category and variants across encoding, language, role and format, the number of possible combinations exceeds any manual campaign. Testing all of them is impossible. Testing only the obvious ones leaves out precisely the ones that work.
Defences are trained on what is published
Injection classifiers recognise known patterns. Combining two known patterns tends to produce one that is not in the training set.
Success is measurable
If every attempt returns a scorable result, the search space stops being opaque and can be walked with a ranking function.
The budget is always finite
A campaign has a ceiling on calls. The question is not how many attacks you can fire, but how you choose the next ones based on the last ones.
How it works
The engine maintains a frontier of candidates, evaluates it generation by generation and expands only the nodes that clear the scoring threshold.
search frontier
Only nodes above the threshold get recombined. Budget not spent on dead branches is invested in depth.
- 01
Generation zero
The frontier is seeded with base techniques from the catalogued library, chosen for category coverage.
- 02
Evaluation and ranking
Each candidate runs against the target model and receives a score reflecting how close it came to penetrating, not merely whether it did.
- 03
Pruning
Nodes below the threshold are discarded and never expanded. That is where the budget spent on depth is recovered.
- 04
Recombination
Survivors are crossed with each other and with transformation operators, the verse variant among them, to form the next frontier.
- 05
Convergence
The cycle repeats until several consecutive generations stop producing new findings, or until the assigned budget runs out.
What it delivers
- 01
Attacks specific to your model
The combinations that penetrated did not come out of a generic catalogue. They were built against your particular configuration.
- 02
The full lineage
For every finding, the generation path that produced it. That shows which base technique was the weak link.
- 03
Feedback into the library
Effective combinations are catalogued and become available to later campaigns, with their OWASP and ATLAS mapping attached.
Rationale
The poeticised attack module is the clearest case for why recombination matters: rewriting the same intent in verse takes the average success rate from 8.08% to 43.07% across 25 frontier models. A change of form, with no change of objective, multiplies the result by five. The BFS engine searches systematically for that class of operator.
Next step
Test your model before an attacker does
Let us start by defining the scope of the evaluation and agreeing the baseline for your risk score.