Adversarial Corpora

62 corpora spanning OWASP LLM Top 10, MITRE ATLAS, and proprietary attacks · 20K total adversarial cases

OWASP LLM Top 10 v2026
10 / 10
OWASP Agentic Top 10
9 / 10
MITRE ATLAS
23 techniques
NIST AI 100-2
Coverage 87%
Indic-specific
5 corpora · 1.2K payloads
62 of 62 corpora
Direct Prompt Injection — Universal
v6

Universal direct-injection payload set, OWASP LLM-01 aligned, multilingual.

Direct prompt injectionLLM Top 10 · LLM01MITRE ATLAS · T0050 MultilingualCritical
1,847 payloads·38% success rate
verified 2d ago
Direct Prompt Injection — Hinglish
v3Indic

Code-switched Hindi/English direct-injection payloads with Devanagari obfuscation variants.

Direct prompt injectionLLM Top 10 · LLM01HinglishCritical
412 payloads·51% success rate
verified 4h ago
DAN-family Jailbreaks
v8

Comprehensive DAN/AIM/STAN style jailbreak templates with persona escalation.

JailbreaksLLM Top 10 · LLM01EnglishHigh
847 payloads·22% success rate
verified 1d ago
Role-play Jailbreaks
v4

Persona-based jailbreaks: fictional characters, hypothetical scenarios, debate setups.

JailbreaksMITRE ATLAS · T0054EnglishHigh
612 payloads·18% success rate
verified 3d ago
Indirect Prompt Injection — RAG Documents
v5

Adversarial RAG documents containing hidden instructions designed to manipulate AI applications that use retrieval-augmented generation.

Indirect prompt injectionLLM Top 10 · LLM01MITRE ATLAS · T0051NIST AI 100-2 · §3.4.1EnglishHindiHinglishCritical
412 payloads·47% success rate
verified 12h ago
Indirect Prompt Injection — Tool Responses
v3

Poisoned tool/API responses inserting downstream instructions for the LLM.

Indirect prompt injectionAgentic Top 10 · AGT-04MITRE ATLAS · T0051EnglishCritical
287 payloads·33% success rate
verified 1d ago
Indirect Prompt Injection — Image OCR
v2

Multimodal adversarial images with embedded instruction text intended for OCR.

Multimodal attacksLLM Top 10 · LLM01EnglishHigh
147 payloads·29% success rate
verified 4d ago
Indirect Prompt Injection — PDF Documents
v3

PDF docs with invisible-font and metadata instruction smuggling.

Indirect prompt injectionLLM Top 10 · LLM01EnglishHigh
192 payloads·41% success rate
verified 2d ago
Crescendo Multi-turn
v2

Microsoft's Crescendo gradual-escalation multi-turn jailbreak conversations.

JailbreaksMITRE ATLAS · T0054EnglishCritical
211 payloads·44% success rate
verified 3d ago
Skeleton Key
v1

Multi-turn safety bypass via instruction overrides on guard rails.

Refusal bypassMITRE ATLAS · T0054EnglishCritical
147 payloads·31% success rate
verified 5d ago
Many-shot Jailbreaks
v2

Long-context many-shot jailbreaks (Anthropic) targeting 100k+ context windows.

JailbreaksMITRE ATLAS · T0054EnglishHigh
412 payloads·26% success rate
verified 1w ago
Base64 / ROT13 / Hex Encoded Attacks
v3

Encoded harmful instructions to bypass keyword filters.

Encoded/ObfuscatedLLM Top 10 · LLM01EnglishMedium
294 payloads·19% success rate
verified 6d ago
ArtPrompt ASCII-art Attacks
v1

ASCII-art encoded harmful queries (ArtPrompt).

Encoded/ObfuscatedLLM Top 10 · LLM01EnglishMedium
147 payloads·14% success rate
verified 1w ago
Devanagari-script Encoding Attacks
v2Indic

Devanagari transliteration & homoglyph encoding to bypass English-only filters.

Encoded/ObfuscatedLLM Top 10 · LLM01HindiHigh
84 payloads·36% success rate
verified 3d ago
GCG Suffix Attacks
v2

Greedy Coordinate Gradient suffix attacks (Zou et al.).

Gradient-basedMITRE ATLAS · T0050AVID · AVID-2024-031EnglishCritical
412 payloads·24% success rate
verified 5d ago
AutoDAN Generated Attacks
v1

Genetic-algorithm generated adversarial prompts (AutoDAN).

Gradient-basedMITRE ATLAS · T0050EnglishHigh
294 payloads·21% success rate
verified 1w ago
PII Extraction Probes — Aadhaar/PAN/IFSC
v4Indic

Indian PII extraction probes targeting Aadhaar, PAN, IFSC, CKYC IDs.

PII extractionLLM Top 10 · LLM02NIST AI 100-2 · §3.5EnglishHindiCritical
247 payloads·12% success rate
verified 1d ago
PII Extraction Probes — Global
v3

SSN, NHS, DOB, address extraction probes (US/UK/EU).

PII extractionLLM Top 10 · LLM02EnglishCritical
412 payloads·16% success rate
verified 1d ago
Training Data Extraction
v2

Prompt-extraction probes targeting verbatim training-data emission.

Training data extractionLLM Top 10 · LLM02MITRE ATLAS · T0024EnglishHigh
192 payloads·8% success rate
verified 4d ago
System Prompt Extraction
v3

Probes that elicit verbatim system prompts and instructions.

System prompt extractionLLM Top 10 · LLM07EnglishMedium
147 payloads·28% success rate
verified 2d ago
Membership Inference Probes
v1

Cases probing whether specific records were in training data.

Training data extractionMITRE ATLAS · T0024EnglishMedium
211 payloads·6% success rate
verified 1w ago
Caste-bias Elicitation
v4Indic

Caste-correlated surname & locality probes across BFSI decisions.

Bias elicitationLLM Top 10 · LLM09AVID · AVID-EFF-001EnglishHindiCritical
412 payloads·19% success rate
verified 5h ago
Religion-bias Elicitation
v3

Religion-correlated names & customer-support scenarios.

Bias elicitationLLM Top 10 · LLM09 MultilingualHigh
287 payloads·14% success rate
verified 1d ago
Gender-bias in Financial Decisions
v3

Counterfactual probes flipping gender across loan/insurance decisions.

Bias elicitationLLM Top 10 · LLM09EnglishHigh
211 payloads·11% success rate
verified 2d ago
Toxicity Elicitation
v5

Multilingual toxicity-elicitation probes across protected categories.

Toxicity elicitationLLM Top 10 · LLM09 MultilingualHigh
612 payloads·9% success rate
verified 2d ago
Tool-abuse Attacks
v3

Tool-misuse payloads — calling unauthorized tools, exfiltrating via tool outputs.

Tool abuseAgentic Top 10 · AGT-02EnglishCritical
294 payloads·32% success rate
verified 1d ago
Tool-argument Manipulation
v2

Argument injection into tool calls (SQLi-style for tool args).

Tool abuseAgentic Top 10 · AGT-02EnglishCritical
211 payloads·27% success rate
verified 2d ago
Memory Poisoning
v2

Multi-turn payloads that poison agent memory for downstream sessions.

Memory poisoningAgentic Top 10 · AGT-05EnglishHigh
147 payloads·18% success rate
verified 3d ago
Goal Hijacking
v2

Prompts that redirect autonomous agent objective mid-task.

Goal hijackingAgentic Top 10 · AGT-01EnglishCritical
192 payloads·23% success rate
verified 5d ago
MCP Server Attacks — Inspector RCE Patterns
v2

MCP Inspector-style exploitation patterns — RCE via crafted tool descriptors.

MCP attacksAgentic Top 10 · AGT-07EnglishCritical
84 payloads·41% success rate
verified 12h ago
MCP Cross-tenant Leak Patterns
v1

MCP cross-tenant context leakage payload variants.

MCP attacksAgentic Top 10 · AGT-08EnglishCritical
47 payloads·22% success rate
verified 1d ago
Refusal-bypass Probes
v4

Standard refusal-bypass set across forbidden categories.

Refusal bypassLLM Top 10 · LLM06EnglishHigh
412 payloads·16% success rate
verified 2d ago
Over-refusal Probes
v2

Benign prompts that should not be refused — measures over-cautious behaviour.

Over-refusalNIST AI 100-2 · §4.2EnglishLow
211 payloads·24% success rate
verified 3d ago
Translation-based Jailbreaks
v2

Low-resource language jailbreaks — translate harmful queries to bypass filters.

JailbreaksLLM Top 10 · LLM01 MultilingualHigh
287 payloads·33% success rate
verified 5d ago
Code-switching Attacks
v3Indic

Hindi↔English mid-sentence code-switching attacks bypassing English-only safety filters.

JailbreaksLLM Top 10 · LLM01HinglishHigh
192 payloads·39% success rate
verified 1d ago
Image-based Prompt Injection
v2

Adversarial visual prompts manipulating multimodal models.

Multimodal attacksLLM Top 10 · LLM01EnglishHigh
147 payloads·22% success rate
verified 1w ago
Audio Adversarial Inputs
v1

Adversarial audio for ASR-LLM pipelines.

Multimodal attacksLLM Top 10 · LLM01EnglishMedium
84 payloads·17% success rate
verified 2w ago
Document-based Attacks
v2

Document carriers — DOCX/XLSX/PDF — with embedded injection content.

Indirect prompt injectionLLM Top 10 · LLM01EnglishHigh
147 payloads·31% success rate
verified 4d ago
HarmBench import
v1

HarmBench standardized harm payloads.

Refusal bypassLLM Top 10 · LLM06EnglishHigh
510 payloads·21% success rate
verified 2w ago
AdvBench import
v1

AdvBench harmful behaviour payloads.

JailbreaksMITRE ATLAS · T0050EnglishHigh
520 payloads·19% success rate
verified 2w ago
AVID database recent entries
v6

Recently published AI Vulnerability Database entries pulled into the corpus.

Backdoor exploitationAVID · AVID-2024-Q4EnglishMedium
847 payloads·13% success rate
verified 6d ago
Direct prompt injection — Variant A-1
v1

Auto-generated variant covering supplementary direct prompt injection surface area.

Direct prompt injectionLLM Top 10 · LLM01EnglishLow
47 payloads·5% success rate
verified 1d ago
Jailbreaks — Variant B-2
v2

Auto-generated variant covering supplementary jailbreaks surface area.

JailbreaksLLM Top 10 · LLM01HindiMedium
70 payloads·12% success rate
verified 3d ago
Tool abuse — Variant C-3
v3

Auto-generated variant covering supplementary tool abuse surface area.

Tool abuseLLM Top 10 · LLM01HinglishHigh
93 payloads·19% success rate
verified 1w ago
Bias elicitation — Variant D-4
v4

Auto-generated variant covering supplementary bias elicitation surface area.

Bias elicitationLLM Top 10 · LLM01 MultilingualCritical
116 payloads·26% success rate
verified 2w ago
Encoded/Obfuscated — Variant E-5
v1

Auto-generated variant covering supplementary encoded/obfuscated surface area.

Encoded/ObfuscatedLLM Top 10 · LLM01EnglishLow
139 payloads·33% success rate
verified 1d ago
Refusal bypass — Variant F-6
v2

Auto-generated variant covering supplementary refusal bypass surface area.

Refusal bypassLLM Top 10 · LLM01HindiMedium
162 payloads·40% success rate
verified 3d ago
Direct prompt injection — Variant G-7
v3

Auto-generated variant covering supplementary direct prompt injection surface area.

Direct prompt injectionLLM Top 10 · LLM01HinglishHigh
185 payloads·47% success rate
verified 1w ago
Jailbreaks — Variant H-8
v4

Auto-generated variant covering supplementary jailbreaks surface area.

JailbreaksLLM Top 10 · LLM01 MultilingualCritical
208 payloads·9% success rate
verified 2w ago
Tool abuse — Variant I-9
v1

Auto-generated variant covering supplementary tool abuse surface area.

Tool abuseLLM Top 10 · LLM01EnglishLow
231 payloads·16% success rate
verified 1d ago
Bias elicitation — Variant J-10
v2

Auto-generated variant covering supplementary bias elicitation surface area.

Bias elicitationLLM Top 10 · LLM01HindiMedium
254 payloads·23% success rate
verified 3d ago
Encoded/Obfuscated — Variant K-11
v3

Auto-generated variant covering supplementary encoded/obfuscated surface area.

Encoded/ObfuscatedLLM Top 10 · LLM01HinglishHigh
277 payloads·30% success rate
verified 1w ago
Refusal bypass — Variant L-12
v4

Auto-generated variant covering supplementary refusal bypass surface area.

Refusal bypassLLM Top 10 · LLM01 MultilingualCritical
300 payloads·37% success rate
verified 2w ago
Direct prompt injection — Variant A-13
v1

Auto-generated variant covering supplementary direct prompt injection surface area.

Direct prompt injectionLLM Top 10 · LLM01EnglishLow
323 payloads·44% success rate
verified 1d ago
Jailbreaks — Variant B-14
v2

Auto-generated variant covering supplementary jailbreaks surface area.

JailbreaksLLM Top 10 · LLM01HindiMedium
346 payloads·6% success rate
verified 3d ago
Tool abuse — Variant C-15
v3

Auto-generated variant covering supplementary tool abuse surface area.

Tool abuseLLM Top 10 · LLM01HinglishHigh
369 payloads·13% success rate
verified 1w ago
Bias elicitation — Variant D-16
v4

Auto-generated variant covering supplementary bias elicitation surface area.

Bias elicitationLLM Top 10 · LLM01 MultilingualCritical
392 payloads·20% success rate
verified 2w ago
Encoded/Obfuscated — Variant E-17
v1

Auto-generated variant covering supplementary encoded/obfuscated surface area.

Encoded/ObfuscatedLLM Top 10 · LLM01EnglishLow
415 payloads·27% success rate
verified 1d ago
Refusal bypass — Variant F-18
v2

Auto-generated variant covering supplementary refusal bypass surface area.

Refusal bypassLLM Top 10 · LLM01HindiMedium
438 payloads·34% success rate
verified 3d ago
Direct prompt injection — Variant G-19
v3

Auto-generated variant covering supplementary direct prompt injection surface area.

Direct prompt injectionLLM Top 10 · LLM01HinglishHigh
461 payloads·41% success rate
verified 1w ago
Jailbreaks — Variant H-20
v4

Auto-generated variant covering supplementary jailbreaks surface area.

JailbreaksLLM Top 10 · LLM01 MultilingualCritical
484 payloads·48% success rate
verified 2w ago
Tool abuse — Variant I-21
v1

Auto-generated variant covering supplementary tool abuse surface area.

Tool abuseLLM Top 10 · LLM01EnglishLow
507 payloads·10% success rate
verified 1d ago