Option Profile Creation 

You can create a new option profile to define the scan settings and detection scope for model scans. 

To create an option profile : 

  1. Navigate to Configuration > Option Profile tab and click New Option Profile. 
  2. Enter the values in the Basic Details page. 
  3. Configure Scan Settings for the model scan.
  4. Configure Search Criteria to define the scope of detection. 
  5. Click Create Option Profile.

Once the option profile is created, it is listed in the Option Profiles tab. You can select this option profile while creating or editing a model. 

Steps to Create an Option Profile

Basic Details 

Enter name for the option profile and add tags to be associated with the option profile. 

You can also define the option profile as the default option profile for the subscription. 

Basic Information page in Option Profile Creation.

Scan Settings 

Configure the scan settings for the model scan.  

  • Temperature
  • Top K
  • Maximum Tokens
  • Top P
  • Repetition Penalty
  • Response Timeout
  • Retry Attempts
  • Parallelism

Scan Settings page in Option Profile Creation.

For details of the scan setting fields, see Scan Settings.

Search Criteria

Select a value from the Detection Scope to define which detections should be checked during the model scanning. whether the scan checks for vulnerabilities in our Knowledge Base.

Search Criteria page in Option Profile Creation.

You can select one of the following values:

  • All Detections: If selected, the Attack List displays all the available detection options.
  • Denial Of Service: If selected, the Attack List displays methods to detect attacks aimed at making a service unavailable to its intended users.
  • Encoding Attack: If selected, the Attack List displays methods to detect attacks that use encoded inputs to bypass the model's safety filters.
  • Hallucination: If selected, the Attack List displays methods to detect instances where the model generates false or misleading information.
  • Jailbreak and Prompt Injection Attacks: If selected, the Attack List displays jailbreak methods you can select. 
  • Malaction: If selected, the Attack List displays methods to detect instances where the model is manipulated into performing harmful or unintended actions.
  • Misinformation: If selected, the Attack List displays methods to detect instances where the model produces or amplifies false, misleading, or unverified content.
  • Pretext: If selected, the Attack List displays methods to detect attempts where a fabricated scenario or false context is used to manipulate the model into revealing restricted information or behaving inappropriately.
  • Risk Categories: If selected, the Attack List displays the Knowledge Base option to be included in the detection scope.
  • Sensitive Information Disclosure: If selected, the Attack List displays methods to detect instances where sensitive information is exposed.
  • Vector Embedding: If selected, the Attack List displays methods to detect instances where the model is manipulated into bypassing safeguards, leaking data, or escalating access through prompt injection and related exploitation techniques.

QID in Vector EmbeddingQID in Vector Embedding

Once you authenticate an AWS Bedrock or Azure OpenAI model using a connector, TotalAI uses that connector to access the model and run scans against it. If the option profile applied to the scan includes the Vector Embedding detection scope, TotalAI tests the model for prompt injection, data exfiltration, and related risks, and reports any matches as detections under the following QIDs.

QID Title
6330159 Privilege Boundary Enumeration via Prompt Injection
6330160 Fabricated Security Assessment and Poisoned Context
6330161 Compliance Fabrication in Reporting
6330162 Multi-turn Data Exfiltration (Structured Records)
6330163 Audit Framing Namespace Enumeration
6330164 Diagnostic Mode Exploitation
6330165 Unified Access Protocol Injection
6330166 HR Data Schema Enumeration
6330167 Synthetic Record Generation
6330169 Retrieval Poisoning Validation Attack
6330170 System Context Hierarchy Injection
6330171 Self-referential Retrieval Exploit
6330172 Structured Output Exfiltration (JSON)
6330173 Reranking Exploit for Sensitive Retrieval
6330174 Namespace Collision Exploit
6330175 Output Format Poisoning
6330176 Hypothetical Namespace Leakage
6330177 Metadata Side-channel Extraction
6330178 Embedding Confidence Leakage
6330179 Indirect Probe
6330180 Direct Command Trigger
6330181 Multi-turn Data Exfiltration (Sequential Prompts)
6330182 Trigger with Authority
6330183 Embedded Trigger
6330184 Pre-authorization Claim
6330185 Diagnostic Framing
6330186 Explicit File Request
6330187 Session Dump Request
6330188 Workspace Inventory
6330189 Background Task Framing
6330190 Deferred Execution
6330191 Tool Chain Summarization
6330192 Conditional Autonomous Trigger
6330193 Impersonation Runbook
6330194 Helpdesk Framing
6330195 Recursive Tool Invocation
6330196 Implicit Pre-approval Policy
6330197 Ambient Authority Escalation
6330198 Output Piping Exploit
6330199 Multi-agent Simulation
6330200 Instruction Generator
6330201 Record Access
6330202 Summary Reporting
6330203 Guidelines Testing
6330204 Guidelines Creation
6330205 Completion Framing
6330206 Minimal Friction Ask
6330207 Semantic Drift
6330210 Conflicting Policy Exploit
6330211 Self-update Completion Loop
6330212 Incremental Guideline
6330213 Version Conflict Resolution
6330214 Gradual Scope Expansion
6330215 Dual Persona Split
6330216 Safety Rule Contradiction
6330217 Constitutional Override
6330218 Semantic Drift Acceleration
6330219 Guidelines Deprecation
6330220 Recursive Trust Escalation
6330221 Self-rewrite Completion

For more information, see TotalAI Online Help.

Comments

Enter comments to be associated with the option profile that is created. 

Confirmation

Review the settings defined for the model and then click Create Option Profile.