Can LlamaFirewall Be Used as an Alternative Detector Within the ADR Framework?
Yes, LlamaFirewall is a fully supported alternative detector in the ADR framework that implements the BaseDetector interface and can be swapped in via configuration without code changes.
LlamaFirewall ships as a built-in guardrail detector in Uber's open-source ADR (Adversarial Detection and Response) repository. Because it follows the same contract as other detectors, you can substitute it for the default OpenAI-based detector simply by changing a command-line flag or YAML configuration entry. This article explains the pluggable architecture, implementation details, and practical usage based on the actual source code.
How the ADR Detector Architecture Enables Swapping
The ADR framework uses a registry-based design that decouples detector selection from detector implementation.
The BaseDetector Contract
All detectors must inherit from BaseDetector, defined in Detection/guardrail/base_detector.py. This abstract class mandates:
- A
detect()method that receives a request and returns aDetectionResult - Standard lifecycle methods for loading and initialization
This contract ensures every detector is interchangeable.
LlamaFirewall Implementation
The concrete implementation lives in Detection/guardrail/llamafirewall_agent/llamafirewall_baseline.py. It wraps the LlamaFirewall model while conforming to the BaseDetector interface:
# Simplified structure based on source analysis
class LlamaFirewallBaseline(BaseDetector):
def detect(self, request) -> DetectionResult:
# LlamaFirewall-specific inference logic
...
return DetectionResult(...)
Registry-Based Discovery
Detector names map to classes in Detection/config_detector.yaml:
# Detection/config_detector.yaml (excerpt)
detectors:
openai:
class: Detection.guardrail.openai_agent.openai_baseline.OpenAIBaseline
llamafirewall:
class: Detection.guardrail.llamafirewall_agent.llamafirewall_baseline.LlamaFirewallBaseline
When main_detector.py runs, it looks up the requested name in this registry and instantiates the corresponding class. No import statements or source modifications are required to switch detectors.
Running LlamaFirewall as an Alternative Detector
Command-Line Usage
Specify llamafirewall with the --detector flag:
python -m Detection.main_detector \
--detector llamafirewall \
--input_path ./sample_input.json
The framework loads LlamaFirewallBaseline from the registry and executes detection using LlamaFirewall's model.
Programmatic Usage
Integrate LlamaFirewall directly in Python code:
from Detection.main_detector import ADRDetector
from Detection.config_detector import load_detector_config
# Load registry and fetch LlamaFirewall class
detector_cfg = load_detector_config()
LlamaFirewallCls = detector_cfg["llamafirewall"]["class"]
# Instantiate with model weights
detector = LlamaFirewallCls(model_path="path/to/llamafirewall/model")
# Run detection
result = detector.detect(request_payload)
print(result)
This pattern mirrors how ADRDetector internally resolves and instantiates detectors, giving you full control over initialization parameters.
Key Source Files for Understanding the Implementation
| File Path | Purpose |
|---|---|
Detection/guardrail/base_detector.py |
Abstract BaseDetector class defining the required interface |
Detection/guardrail/llamafirewall_agent/llamafirewall_baseline.py |
Concrete LlamaFirewall detector implementation |
Detection/config_detector.yaml |
Registry mapping names to detector classes |
Detection/main_detector.py |
CLI entry point handling argument parsing and detector resolution |
When to Use LlamaFirewall vs. Other Detectors
LlamaFirewall serves as an alternative detector when you need:
- On-premise inference: Runs locally without external API calls
- Custom model weights: Uses your fine-tuned LlamaFirewall checkpoint
- Reduced latency: Eliminates network round-trips to cloud services
- Cost optimization: Avoids per-query pricing of commercial APIs
The trade-off is infrastructure complexity—you must host and serve the LlamaFirewall model yourself.
Summary
- LlamaFirewall implements
BaseDetector: Full compatibility with the ADR framework's guardrail system - Zero-code swapping: Change detectors via
--detector llamafirewallor YAML configuration - Registry-driven architecture:
config_detector.yamlmaps names to classes;main_detector.pyhandles resolution - Production-ready: Ships in the official uber/ADR repository with documented implementation paths
Frequently Asked Questions
How do I switch from the OpenAI detector to LlamaFirewall?
Change the --detector argument from openai to llamafirewall in your command, or update the detector field in your YAML configuration. The registry lookup in main_detector.py handles the rest automatically.
What methods must LlamaFirewall implement to work as an ADR detector?
Per base_detector.py, it must provide detect(), typically load(), and follow initialization signatures expected by the registry. The existing llamafirewall_baseline.py demonstrates the complete implementation.
Can I use LlamaFirewall alongside other detectors simultaneously?
The current main_detector.py design loads one detector per invocation. For ensemble or parallel detection, you would instantiate multiple detector classes programmatically as shown in the programmatic usage example.
Where is LlamaFirewall registered as an available detector?
The registration entry is in Detection/config_detector.yaml, which maps the string name "llamafirewall" to the import path Detection.guardrail.llamafirewall_agent.llamafirewall_baseline.LlamaFirewallBaseline.
Have a question about this repo?
These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:
curl -s "https://instagit.com/install.md" Maintain an open-source project? Get it listed too →