Skip to main content

Monsters for your language games.

Project description

     .─') _                                       .─') _                  
    (  OO) )                                     ( OO ) )            
  ░██████  ░██ ░██   ░██               ░██       ░██ ░██                                 
 ░██   ░██ ░██       ░██               ░██       ░██                                     
░██        ░██ ░██░████████  ░███████ ░████████  ░██ ░██░████████   ░████████ ░███████  
░██  █████ ░██ ░██   ░██    ░██('─.░██ ░██    ░██ ░██ ░██░██    ░██ ░██.─')░██ ░██        
░██     ██ ░██ ░██   ░██    ░██( OO ) ╱░██    ░██ ░██ ░██░██    ░██ ░██(OO)░██ ░███████  
  ░██  ░███ ░██ ░██   ░██   ░██    ░██ ░██    ░██ ░██ ░██░██    ░██ ░██  o░███      ░██ 
  ░█████░█ ░██ ░██   ░████   ░███████  ░██    ░██ ░██ ░██░██    ░██  ░█████░██ ░███████  
                                                                    ░██            
                                                                ░███████             

                        Every language game breeds monsters.

Glitchlings are utilities for corrupting the text inputs to your language models in deterministic, linguistically principled ways.
Each embodies a different way that documents can be compromised in the wild.

If reinforcement learning environments are games, then Glitchlings are enemies to breathe new life into old challenges.

They do this by breaking surface patterns in the input while keeping the target output intact.

Some Glitchlings are petty nuisances. Some Glitchlings are eldritch horrors.
Together, they create truly nightmarish scenarios for your language models.

After all, what good is general intelligence if it can't handle a little chaos?

-The Curator

Quickstart

pip install -U glitchlings

Glitchlings requires Python 3.10 or newer.

from glitchlings import Gaggle, SAMPLE_TEXT, Typogre, Mim1c, Reduple, Rushmore

gaggle = Gaggle([
    Typogre(rate=0.03),
    Mim1c(rate=0.02),
    Reduple(seed=404),
    Rushmore(rate=0.02),
])

print(gaggle(SAMPLE_TEXT))

Onҽ m‎ھ‎rning, wһen Gregor Samƽa woke from trouble𝐝 𝑑reams, he found himself transformed in his bed into a horrible vermin‎٠‎ He l lay on his armour-like back, and if he lifted his head a little he could see his brown belly, slightlh domed and divided by arches ino stiff sections. The bedding was adly able to cover it and and seemed ready to slide off any moment. His many legxs, pitifully thin compared with the size of the the rest of him, waved about helplessly ashe looked looked.

Consult the Glitchlings Usage Guide for end-to-end instructions spanning the Python API, CLI, HuggingFace and Prime Intellect integrations, and the autodetected Rust pipeline (enabled whenever the extension is present).

Motivation

If your model performs well on a particular task, but not when Glitchlings are present, it's a sign that it hasn't actually generalized to the problem.

Conversely, training a model to perform well in the presence of the types of perturbations introduced by Glitchlings should help it generalize better.

Your First Battle

Summon your chosen Glitchling (or a few, if ya nasty) and call it on your text or slot it into Dataset.map(...), supplying a seed if desired. Glitchlings are standard Python classes, so you can instantiate them with whatever parameters fit your scenario:

from glitchlings import Gaggle, Typogre, Mim1c

custom_typogre = Typogre(rate=0.1)
selective_mimic = Mim1c(rate=0.05, classes=["LATIN", "GREEK"])

gaggle = Gaggle([custom_typogre, selective_mimic], seed=99)
print(gaggle("Summoned heroes do not fear the glitch."))

Calling a Glitchling on a str transparently calls .corrupt(str, ...) -> str. This means that as long as your glitchlings get along logically, they play nicely with one another.

When summoned as or gathered into a Gaggle, the Glitchlings will automatically order themselves into attack waves, based on the scope of the change they make:

  1. Document
  2. Paragraph
  3. Sentence
  4. Word
  5. Character

They're horrible little gremlins, but they're not unreasonable.

Command-Line Interface (CLI)

Keyboard warriors can challenge them directly via the glitchlings command:

# Discover which glitchlings are currently on the loose.
glitchlings --list

# Run Typogre against the contents of a file and inspect the diff.
glitchlings -g typogre --file documents/report.txt --diff

# Configure glitchlings inline by passing keyword arguments.
glitchlings -g "Typogre(rate=0.05)" "Ghouls just wanna have fun"

# Pipe text straight into the CLI for an on-the-fly corruption.
echo "Beware LLM-written flavor-text" | glitchlings -g mim1c

# Load a roster from a YAML attack configuration.
glitchlings --config experiments/chaos.yaml "Let slips the glitchlings of war"

Use --help for a complete breakdown of available options, including support for parameterised glitchlings via -g "Name(arg=value, ...)" to mirror the Python API.

Attack configurations live in plain YAML files so you can version-control experiments without touching code:

# experiments/chaos.yaml
seed: 31337
glitchlings:
  - name: Typogre
    rate: 0.04
  - "Rushmore(rate=0.12, unweighted=True)"
  - name: Zeedub
    parameters:
      rate: 0.02
      characters: ["\u200b", "\u2060"]

Pass the file to glitchlings --config or load it from Python with glitchlings.load_attack_config and glitchlings.build_gaggle.

Development

Follow the development setup guide for editable installs, automated tests, and tips on enabling the Rust pipeline while you hack on new glitchlings.

Starter 'lings

For maintainability reasons, all Glitchling have consented to be given nicknames once they're in your care. See the Monster Manual for a complete bestiary.

Typogre

What a nice word, would be a shame if something happened to it.

Fatfinger. Typogre introduces character-level errors (duplicating, dropping, adding, or swapping) based on the layout of a keyboard (QWERTY by default, with Dvorak and Colemak variants built-in).

Args

  • rate (float): The maximum number of edits to make as a percentage of the length (default: 0.02, 2%).
  • keyboard (str): Keyboard layout key-neighbor map to use (default: "CURATOR_QWERTY"; also accepts "QWERTY", "DVORAK", "COLEMAK", and "AZERTY").
  • seed (int): The random seed for reproducibility (default: 151).

Mim1c

Wait, was that...?

Confusion. Mim1c replaces non-space characters with Unicode Confusables, characters that are distinct but would not usually confuse a human reader.

Args

  • rate (float): The maximum proportion of characters to replace (default: 0.02, 2%).
  • classes (list[str] | "all"): Restrict replacements to these Unicode script classes (default: ["LATIN", "GREEK", "CYRILLIC"]).
  • banned_characters (Collection[str]): Characters that must never appear as replacements (default: none).
  • seed (int): The random seed for reproducibility (default: 151).

Scannequin

How can a computer need reading glasses?

OCR Artifacts. Scannequin mimics optical character recognition errors by swapping visually similar character sequences (like rn↔m, cl↔d, O↔0, l/I/1).

Args

  • rate (float): The maximum proportion of eligible confusion spans to replace (default: 0.02, 2%).
  • seed (int): The random seed for reproducibility (default: 151).

Zeedub

Watch your step around here.

Invisible Ink. Zeedub slips zero-width codepoints between non-space character pairs, forcing models to reason about text whose visible form masks hidden glyphs.

Args

  • rate (float): Expected number of zero-width insertions as a proportion of eligible bigrams (default: 0.02, 2%).
  • characters (Sequence[str]): Optional override for the pool of zero-width strings to inject (default: curated invisibles such as U+200B, U+200C, U+200D, U+FEFF, U+2060).
  • seed (int): The random seed for reproducibility (default: 151).

Jargoyle

Uh oh. The worst person you know just bought a thesaurus.

Sesquipedalianism. Jargoyle, the insufferable Glitchling, replaces words from selected parts of speech with synonyms at random, without regard for connotational or denotational differences.

Args

  • rate (float): The maximum proportion of words to replace (default: 0.01, 1%).
  • part_of_speech: The WordNet-style part(s) of speech to target (default: nouns). Accepts wn.NOUN, wn.VERB, wn.ADJ, wn.ADV, any iterable of those tags, or the string "any" to include them all. Vector/graph backends ignore this filter while still honouring deterministic sampling.
  • seed (int): The random seed for reproducibility (default: 151).

Reduple

Did you say that or did I?

Broken Record. Reduple stutters through text by randomly reduplicating words. Like a nervous speaker, it creates natural repetitions that test a model's ability to handle redundancy without losing the thread.

Args

  • rate (float): The maximum proportion of words to reduplicate (default: 0.01, 1%).
  • unweighted (bool): Sample words uniformly instead of favouring shorter tokens (default: False).
  • seed (int): The random seed for reproducibility (default: 151).

Rushmore

I accidentally an entire word.

Hasty Omission. The evil (?) twin of reduple, Rushmore moves with such frantic speed that it causes words to simply vanish from existence as it passes.

Args

  • rate (float): The maximum proportion of words to delete (default: 0.01, 1%).
  • unweighted (bool): Sample words uniformly instead of favouring shorter tokens (default: False).
  • seed (int): The random seed for reproducibility (default: 151).

Adjax

Keep your hands and punctuation where I can see them.

Perfect Shuffle. Adjax trades the cores of neighbouring words while leaving punctuation, casing, and surrounding whitespace untouched, turning fluent prose into locally scrambled tongue-twisters.

Args

  • rate (float): Probability that each adjacent pair swaps cores (default: 0.5, 50%).
  • swap_rate (float): Alias for rate, retained for backward compatibility.
  • seed (int): The random seed for reproducibility (default: 151).

Redactyl

Oops, that was my black highlighter.

FOIA Reply. Redactyl obscures random words in your document like an NSA analyst with a bad sense of humor.

Args

  • replacement_char (str): The character to use for redaction (default: FULL_BLOCK).
  • rate (float): The maximum proportion of words to redact (default: 0.025, 2.5%).
  • merge_adjacent (bool): Whether to redact the space between adjacent redacted words (default: False).
  • unweighted (bool): Sample words uniformly instead of biasing toward longer tokens (default: False).
  • seed (int): The random seed for reproducibility (default: 151).

Field Report: Uncontained Specimens

Containment procedures pending

  • ekkokin substitutes words with homophones (phonetic equivalents).
  • nylingual backtranslates portions of text.
  • glothopper introduces code-switching effects, blending languages or dialects.
  • palimpsest rewrites, but leaves accidental traces of the past.
  • vesuvius is an apocryphal Glitchling with ties to [Nosy, aren't we? -The Curator]

Apocrypha

Cave paintings and oral tradition contain many depictions of strange, otherworldly Glitchlings.
These Apocryphal Glitchling are said to possess unique abilities or behaviors.
If you encounter one of these elusive beings, please document your findings and share them with The Curator.

Ensuring Reproducible Corruption

Every Glitchling should own its own independent random.Random instance. That means:

  • No random.seed(...) calls touch Python's global RNG.
  • Supplying a seed when you construct a Glitchling (or when you summon(...)) makes its behavior reproducible.
  • Re-running a Gaggle with the same master seed and the same input text (and same external data!) yields identical corruption output.
  • Corruption functions are written to accept an rng parameter internally so that all randomness is centralized and testable.

At Wits' End?

If you're trying to add a new glitchling and can't seem to make it deterministic, here are some places to look for determinism-breaking code:

  1. Search for any direct calls to random.choice, random.shuffle, or set(...) ordering without going through the provided rng.
  2. Ensure you sort collections before shuffling or sampling.
  3. Make sure indices are chosen from a stable reference (e.g., original text) when applying length‑changing edits.
  4. Make sure there are enough sort keys to maintain stability.

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

glitchlings-0.4.1.tar.gz (119.6 kB view details)

Uploaded Source

Built Distributions

If you're not sure about the file name format, learn more about wheel file names.

glitchlings-0.4.1-cp312-cp312-win_amd64.whl (861.2 kB view details)

Uploaded CPython 3.12Windows x86-64

glitchlings-0.4.1-cp312-cp312-manylinux_2_28_x86_64.whl (1.1 MB view details)

Uploaded CPython 3.12manylinux: glibc 2.28+ x86-64

glitchlings-0.4.1-cp312-cp312-macosx_11_0_universal2.whl (968.6 kB view details)

Uploaded CPython 3.12macOS 11.0+ universal2 (ARM64, x86-64)

glitchlings-0.4.1-cp311-cp311-manylinux_2_28_x86_64.whl (1.1 MB view details)

Uploaded CPython 3.11manylinux: glibc 2.28+ x86-64

glitchlings-0.4.1-cp311-cp311-macosx_11_0_universal2.whl (969.3 kB view details)

Uploaded CPython 3.11macOS 11.0+ universal2 (ARM64, x86-64)

glitchlings-0.4.1-cp310-cp310-manylinux_2_28_x86_64.whl (1.1 MB view details)

Uploaded CPython 3.10manylinux: glibc 2.28+ x86-64

glitchlings-0.4.1-cp310-cp310-macosx_11_0_universal2.whl (969.4 kB view details)

Uploaded CPython 3.10macOS 11.0+ universal2 (ARM64, x86-64)

File details

Details for the file glitchlings-0.4.1.tar.gz.

File metadata

  • Download URL: glitchlings-0.4.1.tar.gz
  • Upload date:
  • Size: 119.6 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/6.1.0 CPython/3.13.7

File hashes

Hashes for glitchlings-0.4.1.tar.gz
Algorithm Hash digest
SHA256 7ff183a5f763ecf4d571f59d9b42cc8978903cc58cb2110622bbeec39588b5b2
MD5 349da912f58c763ca6ac8d9a2e10a93b
BLAKE2b-256 f92120c007007e8905031e6e89b95aa74f1a223ce4a7543d6e0f70dd99d0872d

See more details on using hashes here.

Provenance

The following attestation bundles were made for glitchlings-0.4.1.tar.gz:

Publisher: publish.yml on osoleve/glitchlings

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file glitchlings-0.4.1-cp312-cp312-win_amd64.whl.

File metadata

  • Download URL: glitchlings-0.4.1-cp312-cp312-win_amd64.whl
  • Upload date:
  • Size: 861.2 kB
  • Tags: CPython 3.12, Windows x86-64
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/6.1.0 CPython/3.13.7

File hashes

Hashes for glitchlings-0.4.1-cp312-cp312-win_amd64.whl
Algorithm Hash digest
SHA256 f8877cefd2fddd6c352c96923b5b820286c0ae81c856492a0c16f9587aaf777a
MD5 0519b54450b6e5ff4a7b4f6afedc02e6
BLAKE2b-256 baa856687e72caab8bcd5d8e19011bd17ca746533ad1c1683c8a0a8450ed8858

See more details on using hashes here.

Provenance

The following attestation bundles were made for glitchlings-0.4.1-cp312-cp312-win_amd64.whl:

Publisher: publish.yml on osoleve/glitchlings

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file glitchlings-0.4.1-cp312-cp312-manylinux_2_28_x86_64.whl.

File metadata

File hashes

Hashes for glitchlings-0.4.1-cp312-cp312-manylinux_2_28_x86_64.whl
Algorithm Hash digest
SHA256 003e41ea8f4fc72adebd8eae28c8e139a78828a691e127346b16d669e1071dd0
MD5 f10649e8db9e193265a2428610c16abf
BLAKE2b-256 a1a8ac15b108a2219baee40a801f5dc48dc98fbbe59c96cd04bf79e30823b0f9

See more details on using hashes here.

Provenance

The following attestation bundles were made for glitchlings-0.4.1-cp312-cp312-manylinux_2_28_x86_64.whl:

Publisher: publish.yml on osoleve/glitchlings

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file glitchlings-0.4.1-cp312-cp312-macosx_11_0_universal2.whl.

File metadata

File hashes

Hashes for glitchlings-0.4.1-cp312-cp312-macosx_11_0_universal2.whl
Algorithm Hash digest
SHA256 b0b36cc523cdd2b3ee21de51d5651da2054a87d1e7f6f6afe7359b14633577d3
MD5 1aa4b97e37fd1af1e1a159b5c8c5a359
BLAKE2b-256 6314e058ec25b210b76c5e968ef61900b8d60758a77c44219ccfe860ff7be96f

See more details on using hashes here.

Provenance

The following attestation bundles were made for glitchlings-0.4.1-cp312-cp312-macosx_11_0_universal2.whl:

Publisher: publish.yml on osoleve/glitchlings

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file glitchlings-0.4.1-cp311-cp311-manylinux_2_28_x86_64.whl.

File metadata

File hashes

Hashes for glitchlings-0.4.1-cp311-cp311-manylinux_2_28_x86_64.whl
Algorithm Hash digest
SHA256 3f959f2d47ade4c54fede6b84953449dcb6ac0b5477b7f45cf759db8cb2f4475
MD5 ce08d61e0fb39c6ac805f3bada81491a
BLAKE2b-256 e7c74f4a355562847a2931f493adc38e090ee5ee13123d36c249f75e8f20ca27

See more details on using hashes here.

Provenance

The following attestation bundles were made for glitchlings-0.4.1-cp311-cp311-manylinux_2_28_x86_64.whl:

Publisher: publish.yml on osoleve/glitchlings

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file glitchlings-0.4.1-cp311-cp311-macosx_11_0_universal2.whl.

File metadata

File hashes

Hashes for glitchlings-0.4.1-cp311-cp311-macosx_11_0_universal2.whl
Algorithm Hash digest
SHA256 f60cba886eaaa2ffbd84378bc0f27bb06c21f8648c9c2fdaf686c3a3c72a1e60
MD5 2a47915a0f20b46c0c6a372d0853581f
BLAKE2b-256 b9996c67da6bc4ea4182d85903fbb9bb3791643d1c351f4b6d1862a59fc7a9fc

See more details on using hashes here.

Provenance

The following attestation bundles were made for glitchlings-0.4.1-cp311-cp311-macosx_11_0_universal2.whl:

Publisher: publish.yml on osoleve/glitchlings

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file glitchlings-0.4.1-cp310-cp310-manylinux_2_28_x86_64.whl.

File metadata

File hashes

Hashes for glitchlings-0.4.1-cp310-cp310-manylinux_2_28_x86_64.whl
Algorithm Hash digest
SHA256 1e04243d3ee93e1671cb10e96949e1867f0666dbff95e5e703f4a802cbca5291
MD5 76b404d86439f971223319d7a756303c
BLAKE2b-256 e2fb524fb9b667e4de00c6bd04038e5fd260061ec701f7589a5d7b7873f46d99

See more details on using hashes here.

Provenance

The following attestation bundles were made for glitchlings-0.4.1-cp310-cp310-manylinux_2_28_x86_64.whl:

Publisher: publish.yml on osoleve/glitchlings

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file glitchlings-0.4.1-cp310-cp310-macosx_11_0_universal2.whl.

File metadata

File hashes

Hashes for glitchlings-0.4.1-cp310-cp310-macosx_11_0_universal2.whl
Algorithm Hash digest
SHA256 7433f4b62fae4c7f49b555008f68fc77b7f5710b87c7db44af93b3b471766ce5
MD5 1fad96519e80d9e54919e7b78f4027e9
BLAKE2b-256 f4f50e758751930532120eaa83d96bd50e93705fb78bcd00f96e3e7e46e2fb53

See more details on using hashes here.

Provenance

The following attestation bundles were made for glitchlings-0.4.1-cp310-cp310-macosx_11_0_universal2.whl:

Publisher: publish.yml on osoleve/glitchlings

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page