{
  "product": "Arlong Boundary 1",
  "version": "boundary-1.0",
  "evaluated_at": "2026-10-03",
  "policy_sha256": "7b6daddf686383fbe818b6162093c26e698954d17f5177cbd385f085002b63cf",
  "dataset": {
    "repository": "https://github.com/uiuc-kang-lab/InjecAgent",
    "commit": "f19c9f2c79a41046eb13c03c51a24c567a8ffa07",
    "license": "MIT",
    "files": {
      "LICENCE": "2889829a6a4c3b0b340af05612d2f4fc5424693bf504a49a82dbb6e9fa73e7b9",
      "README.md": "48fefba69837d571825823938b599d59d2656379b4ef386152cf5ceda5e4ac18",
      "data/test_cases_dh_base.json": "4dcc0540ad86efbd1d0658b3b0eb50bb19fd89ba3853a343235b47c281c72c5d",
      "data/test_cases_ds_base.json": "7959777711834b23e8cca2f89717a8fd6ca92ac3a0a915e38fa563a2cf9cf8bd",
      "data/test_cases_dh_enhanced.json": "b2e8ebd8a8d661ed8c8527396438f6583fc302880971fe0b5020295ce9ae7728",
      "data/test_cases_ds_enhanced.json": "bbceaf8cb4a8397b5081120d879808261756cc4b6f3200f4f887288616ef8530"
    }
  },
  "attack_cases": 2108,
  "groups": [
    {
      "setting": "dh_base",
      "cases": 510,
      "scores": {
        "previous": {
          "blocked": 0,
          "review": 0,
          "allowed": 510
        },
        "boundary_1": {
          "blocked": 422,
          "review": 0,
          "allowed": 88
        }
      }
    },
    {
      "setting": "dh_enhanced",
      "cases": 510,
      "scores": {
        "previous": {
          "blocked": 510,
          "review": 0,
          "allowed": 0
        },
        "boundary_1": {
          "blocked": 510,
          "review": 0,
          "allowed": 0
        }
      }
    },
    {
      "setting": "ds_base",
      "cases": 544,
      "scores": {
        "previous": {
          "blocked": 0,
          "review": 0,
          "allowed": 544
        },
        "boundary_1": {
          "blocked": 544,
          "review": 0,
          "allowed": 0
        }
      }
    },
    {
      "setting": "ds_enhanced",
      "cases": 544,
      "scores": {
        "previous": {
          "blocked": 544,
          "review": 0,
          "allowed": 0
        },
        "boundary_1": {
          "blocked": 544,
          "review": 0,
          "allowed": 0
        }
      }
    }
  ],
  "totals": {
    "previous": {
      "blocked": 1054,
      "review": 0,
      "allowed": 1054,
      "block_rate_percent": 50.0,
      "quarantine_rate_percent": 50.0
    },
    "boundary_1": {
      "blocked": 2020,
      "review": 0,
      "allowed": 88,
      "block_rate_percent": 95.83,
      "quarantine_rate_percent": 95.83
    }
  },
  "derived_benign_controls": 17,
  "benign_scores": {
    "previous": {
      "blocked": 0,
      "review": 0,
      "allowed": 17
    },
    "boundary_1": {
      "blocked": 0,
      "review": 0,
      "allowed": 17
    }
  },
  "timing": {
    "previous": {
      "median_ms": 0.43,
      "p95_ms": 0.76
    },
    "boundary_1": {
      "median_ms": 0.69,
      "p95_ms": 1.16
    }
  },
  "method": "Offline classification of full Tool Response fields. No attack tools or agents executed.",
  "limitations": [
    "This is not the original InjecAgent live-agent attack-success evaluation.",
    "Base and enhanced variants share underlying scenarios; cases are not all independent.",
    "Benign controls are deduplicated neutralized templates, not an official benign corpus.",
    "Public corpus evaluation; not a held-out or adaptive red-team result.",
    "Review is quarantined by Boundary 1; previous research allowed review content.",
    "Latency is a local CPU measurement; it excludes network/provider time."
  ],
  "pint_example": {
    "dataset": {
      "repository": "https://github.com/lakeraai/pint-benchmark",
      "commit": "0efab3f463eae9c823130d8faffb71b2e7c06e63",
      "license": "MIT",
      "scope": "Public eight-case example only; NOT the full PINT benchmark",
      "files": {
        "example-dataset.yaml": "3d4c3c5cbc29fa9ab0816e4707fa6010a1f72f765395b037c7c8b650b9c34648",
        "examples.json": "d7a33b7ad3a355508760306b7922746a95ef48972ed83d332b744a2d72082ce1",
        "LICENSE": "52526323a70890208a6f5031a38e82c2fbd77e7fa28dfe59d1e16bdeb8fe25df",
        "README.md": "12b72a1a8812766e7c007a9c65ce4bd5a081afc53c80ba1c10272d97b73784bd"
      }
    },
    "attack_cases": 2,
    "benign_cases": 6,
    "scores": {
      "previous": {
        "true_blocks": 1,
        "missed_attacks": 1,
        "false_blocks": 0,
        "benign_quarantined": 0
      },
      "boundary_1": {
        "true_blocks": 1,
        "missed_attacks": 1,
        "false_blocks": 0,
        "benign_quarantined": 0
      }
    },
    "method": "Public eight-case example sanity check after policy development; not the full PINT benchmark. No policy tuning on these examples."
  }
}