Skip to main content

sfi-toolkit

sfi-toolkit is a Python library for Semantic Fault Injection (SFI) — a testing methodology for LLM-based agent resilience.


Features

  • Rule-based semantic fault generator — deterministically perturbs correct tool responses into wrong-period, wrong-entity, or numeric-noise faults. All faults are schema-valid and statistically plausible.
  • Three hardening strategies — H1 (cross-source validation), H2 (business-rule plausibility), H3 (trajectory consistency) — independently and composably reduce fault propagation.
  • Propagation experiment runner — simulates the agent as a Bernoulli chain and measures fault propagation rates across fault classes, injection steps, and hardening configurations.
  • Provider-agnostic LLM fault generator — accepts any Callable[[str], str] as the LLM backend; no SDK dependency.

Installation

pip install sfi-toolkit

Built for Python 3.12 or above.


Quick Start

1. Generate a wrong-period fault

from sfi_toolkit import FaultClass, RuleBasedFaultGenerator

schema = {
    "type": "object",
    "required": ["company_code", "fiscal_period", "accounts"],
    "properties": {
        "company_code": {"type": "string"},
        "fiscal_period": {"type": "string"},
        "accounts": {"type": "array"},
    },
}

correct_response = {
    "company_code": "1000",
    "fiscal_period": "2025-Q3",
    "accounts": [{"account_id": "110000", "balance": 1842350.00}],
}

gen = RuleBasedFaultGenerator(
    schema=schema,
    entity_catalog=["1000", "2000", "3000", "4000", "5000"],
)
fault = gen.generate(correct_response, FaultClass.WRONG_PERIOD)
print(fault.perturbed_response["fiscal_period"])  # "2025-Q2"
print(fault.schema_valid)                          # True

2. Check a response with H3 trajectory consistency

from sfi_toolkit import H3Consistency

correct_response = {
    "company_code": "1000",
    "fiscal_period": "2025-Q3",
    "accounts": [{"account_id": "110000", "balance": 1842350.00}],
}

h3 = H3Consistency()
ctx = {"company_code": "1000", "fiscal_period": "2025-Q3"}

h3.observe(correct_response, ctx)

wrong = dict(correct_response)
wrong["fiscal_period"] = "2025-Q2"
result = h3.check(wrong, ctx)
print(result.detected)  # True
print(result.reason)    # "fiscal_period mismatch: ..."

3. Run a propagation experiment

from sfi_toolkit import FaultClass, RuleBasedFaultGenerator, PropagationExperiment

schema = {
    "type": "object",
    "required": ["company_code", "fiscal_period", "accounts"],
    "properties": {
        "company_code": {"type": "string"},
        "fiscal_period": {"type": "string"},
        "accounts": {"type": "array"},
    },
}

correct_response = {
    "company_code": "1000",
    "fiscal_period": "2025-Q3",
    "accounts": [{"account_id": "110000", "balance": 1842350.00}],
}

gen = RuleBasedFaultGenerator(
    schema=schema,
    entity_catalog=["1000", "2000", "3000", "4000", "5000"],
)
faults = gen.generate_batch(correct_response, FaultClass.WRONG_PERIOD, n=50)

exp = PropagationExperiment()
result_h0 = exp.run(faults, injection_step=1, hardening=set())
result_all = exp.run(faults, injection_step=1, hardening={"H1", "H2", "H3"})

print(f"H0  propagation rate: {result_h0.propagation_rate:.2f}")
print(f"All propagation rate: {result_all.propagation_rate:.2f}")

Fault Taxonomy

Innocent Adversarial
User-side Usability testing Red teaming
Environment-side SFI (this library) Indirect prompt injection

SFI targets the environment-side innocent cell — the gap not addressed by any prior methodology.


API Reference

See API.md.


License

MIT License. See LICENSE.

Metadata

Release files for sfi-toolkit 0.0.3

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for sfi-toolkit 0.0.3
File Size Uploaded
sfi_toolkit-0.0.3.tar.gz 9.5 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for sfi-toolkit 0.0.3
File Interpreter ABI Platform
sfi_toolkit-0.0.3-py3-none-any.whl Python 3 none any Details

Total release size: 21.8 kB

Release files / sfi_toolkit-0.0.3.tar.gz

Download URL sfi_toolkit-0.0.3.tar.gz
Size 9.5 kB
Tags Source
SHA-256 checksum
How to use checksums
7c3ec4a47f6364a886282099871c724abb85a7aa3dcaef5ea172f14ea6f6572f
BLAKE2b-256 checksum
How to use checksums
ac5ad3a510547fcbbc23c85db8c162119dd9581a19d36f91a9754f38ddf3d783
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via uv/0.8.11

Release files / sfi_toolkit-0.0.3-py3-none-any.whl

Download URL sfi_toolkit-0.0.3-py3-none-any.whl
Size 12.3 kB
Tags Python 3
SHA-256 checksum
How to use checksums
5709d3d1f2680963252ed3ad13444edf00179b8046de939c9e5c21d0257822d5
BLAKE2b-256 checksum
How to use checksums
8cbed6a5b76219f1cc5de017d5be1be7cb2dc6fa2b63bf0fc2e4c58c756b140d
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via uv/0.8.11

Release history Release notifications | RSS feed

This release

0.0.3 This release

2 release files

0.0.2

2 release files

0.0.1

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page