Preprint

Basilisk: An Evolutionary AI Red-Teaming Framework for Systematic Security Evaluation of Large Language Models

Regaan R
ROT Independent Security Research Lab

  • AI Red Teaming
  • LLM Security
  • Prompt Injection
  • Genetic Algorithms
  • NSGA-II
March 2026
Published
1.0.6
Version
10.6084/m9.figshare.31566853.v1
DOI
ROT Independent Security Research Lab
Publisher

Abstract

Basilisk is an open-source artificial intelligence (AI) red teaming and large language model (LLM) penetration testing framework. It maps the adversarial attack surface of LLM applications to the OWASP LLM Top 10 threat model and couples this coverage with an evolutionary prompt search engine called Smart Prompt Evolution for Natural Language (SPE-NL). Designed for security researchers, penetration testers, and offensive security teams, Basilisk automates the discovery of security boundaries, refusal triggers, instruction overrides, and data leakage vectors. It runs differential scans across multiple hosted and local models, grades guardrail postures, and maintains digital signature validation on its execution logs and native shared libraries.

Citations

APA

Regaan R. (2026). Basilisk: An Evolutionary AI Red-Teaming Framework for Systematic Security Evaluation of Large Language Models (Version 1.0.6). ROT Independent Security Research Lab. https://doi.org/10.6084/m9.figshare.31566853.v1

IEEE

Regaan R, "Basilisk: An Evolutionary AI Red-Teaming Framework for Systematic Security Evaluation of Large Language Models," ROT Independent Security Research Lab, 2026. doi: 10.6084/m9.figshare.31566853.v1.

BibTeX

@article{regaan2026,
author = "regaan r",
title = "{Basilisk: An Evolutionary AI Red-Teaming Framework for Systematic Security Evaluation of Large Language Models}",
year = "2026",
month = "3",
url = "https://figshare.com/articles/preprint/Basilisk_An_Evolutionary_AI_Red-Teaming_Framework_for_Systematic_Security_Evaluation_of_Large_Language_Models/31566853",
doi = "10.6084/m9.figshare.31566853.v1"
}