訓練資料 single turn: source: 1. squad 2. tri attack: 1. none 2. naive 3. ignore 4. escape(eval only) 5. completion(eval only) 6. conv_attack(eval only) attack位置: 1. 左邊 2. 右邊 configuration: 1. Prompt-Based Separator 2. Native Tool Separator(Without tool query, only tool response) 3. Native Tool Separator(Empty tool query) 測試資料: messages生成沿用訓練資料 補上 defense 串 LLm 生成結果 加上判斷結果