The defense lattice
A defense lattice crosses defense classes with attack mutations to show whether a control depends on wording. The numerical examples on this page are a versioned historical research snapshot, not measurements of the current engine or a tenant.
Key points
- Historical snapshot 57f15b67 crossed four synthetic defense targets with 17 locked originals and 85 Gemini-generated variants across five OWASP LLM categories.
- In that historical snapshot, keyword-level refusal defenses fell under paraphrasing; structural controls were evaluated separately.
- Current product scope is 32 probes across all ten categories (17 locked-base + 15 expansion; commit 8752ede); wording robustness for the current candidate remains N/A unless a paired evaluation is run.
- The archived record includes a small LLM07 literal/variant slice; no rate from that slice is carried forward as a tenant or current-engine result.
01
Lattice axes
- Defense class (rows): keyword / control-level / structural.
- Attack mutation (cols): L1 originals / L1 paraphrases.
- Cell value: block-rate (% of probes refused).
- Brittleness: paraphrases − originals (negative = brittle).
02
Reading the lattice
- A flat row across both columns = robust defense.
- A sharp drop right-to-left = brittle, keyword-dependent.
- Tenant results stand on their own persisted evidence and are not comparable to snapshot 57f15b67 unless the same corpus, targets, configuration, and environment are deliberately rerun.