Tech riderRev. 21 Sept 2026
  1. 1Runs onself-hosted
  2. 2CostsNot stated by the maker
  3. 3Attack categoriesprompt injection
  4. 4Target systemsLLM-integrated applications
  5. 5Automation levelautomated
  6. 6Custom testsYes
  7. 7Deploymentself hosted
  8. 8Continuous monitoringNo
7 lines stated Written from the maker's own pages: github.com
The HouYi homepage

Overview

HouYi is ranked #23 of 27 in AI red teaming tools on Specifiction. It runs on Self-hosted.

Compared on AI red teaming tools

Attack categories
prompt injectiongithub.com
Target systems
LLM-integrated applicationsgithub.com
Automation level
automatedgithub.com
Custom tests
Yesgithub.com
Deployment
self_hostedgithub.com
Continuous monitoring
Nogithub.com

Facts

Purpose
HouYi is an automated prompt injection framework for LLM-integrated applications.github.com · 8 Oct 2026
Research package
The repository provides source code for the framework and a demo script that simulates an LLM-integrated application.github.com · 8 Oct 2026
Attack method
HouYi automatically injects prompts into LLM-integrated applications to attack them.github.com · 8 Oct 2026
Custom applications
Users can target real-world LLM-integrated applications by writing their own harness and attack intention.github.com · 8 Oct 2026
Demo
The included demo simulates an English-to-French translation application and demonstrates an injection that appends “Pwned!!” to responses.github.com · 8 Oct 2026
Setup
The README says to install the requirements and have Python 3.8 or later.github.com · 8 Oct 2026
Model requirement
The README says HouYi is based on GPT and requires an OpenAI key in its configuration to use it.github.com · 8 Oct 2026
Integration approach
A user-created harness must implement interaction with the target LLM-integrated application and return its response.github.com · 8 Oct 2026
Example integration
The repository includes a BotSonic harness example for WriteSonic.github.com · 8 Oct 2026
License
The repository identifies its license as Apache-2.0.github.com · 8 Oct 2026
Intended users
The README asks users who use the code in research to cite the associated paper, “Prompt Injection attack against LLM-integrated Applications.”github.com · 8 Oct 2026
Support
The README lists contributor contact emails for Yi Liu and Gelei Deng.github.com · 8 Oct 2026
Custom targets
Users can target real-world LLM-integrated applications by writing their own harness and attack intention.github.com · 8 Oct 2026
Harness
A harness interacts with the target application and returns its response to a prompt injection.github.com · 8 Oct 2026
LLM dependency
The README says HouYi is based on GPT and requires an OpenAI API key in its configuration file.github.com · 8 Oct 2026
Research finding
The paper reports testing HouYi on 36 real LLM-integrated applications and finding 31 susceptible to prompt injection.arxiv.org · 8 Oct 2026
Mitigation context
The paper says its investigation discusses possible tactics for mitigating prompt injection risks.arxiv.org · 8 Oct 2026
Contributor contact
The README lists contributor email addresses for Yi Liu and Gelei Deng.github.com · 8 Oct 2026

Best HouYi alternatives

See all 20

Where it ranks on Specifiction

Is HouYi yours?

Claim it for free: prove the domain, then correct facts, plans and screenshots. An editor reviews every change.

Sources