Can LlamaFirewall Be Used as an Alternative Detector Within the ADR Framework?

Yes, LlamaFirewall is a fully supported alternative detector in the ADR framework that implements the BaseDetector interface and can be swapped in via configuration without code changes.

LlamaFirewall ships as a built-in guardrail detector in Uber's open-source ADR (Adversarial Detection and Response) repository. Because it follows the same contract as other detectors, you can substitute it for the default OpenAI-based detector simply by changing a command-line flag or YAML configuration entry. This article explains the pluggable architecture, implementation details, and practical usage based on the actual source code.

How the ADR Detector Architecture Enables Swapping

The ADR framework uses a registry-based design that decouples detector selection from detector implementation.

The BaseDetector Contract

All detectors must inherit from BaseDetector, defined in Detection/guardrail/base_detector.py. This abstract class mandates:

  • A detect() method that receives a request and returns a DetectionResult
  • Standard lifecycle methods for loading and initialization

This contract ensures every detector is interchangeable.

LlamaFirewall Implementation

The concrete implementation lives in Detection/guardrail/llamafirewall_agent/llamafirewall_baseline.py. It wraps the LlamaFirewall model while conforming to the BaseDetector interface:


# Simplified structure based on source analysis

class LlamaFirewallBaseline(BaseDetector):
    def detect(self, request) -> DetectionResult:
        # LlamaFirewall-specific inference logic

        ...
        return DetectionResult(...)

Registry-Based Discovery

Detector names map to classes in Detection/config_detector.yaml:


# Detection/config_detector.yaml (excerpt)

detectors:
  openai:
    class: Detection.guardrail.openai_agent.openai_baseline.OpenAIBaseline
  llamafirewall:
    class: Detection.guardrail.llamafirewall_agent.llamafirewall_baseline.LlamaFirewallBaseline

When main_detector.py runs, it looks up the requested name in this registry and instantiates the corresponding class. No import statements or source modifications are required to switch detectors.

Running LlamaFirewall as an Alternative Detector

Command-Line Usage

Specify llamafirewall with the --detector flag:

python -m Detection.main_detector \
    --detector llamafirewall \
    --input_path ./sample_input.json

The framework loads LlamaFirewallBaseline from the registry and executes detection using LlamaFirewall's model.

Programmatic Usage

Integrate LlamaFirewall directly in Python code:

from Detection.main_detector import ADRDetector
from Detection.config_detector import load_detector_config

# Load registry and fetch LlamaFirewall class

detector_cfg = load_detector_config()
LlamaFirewallCls = detector_cfg["llamafirewall"]["class"]

# Instantiate with model weights

detector = LlamaFirewallCls(model_path="path/to/llamafirewall/model")

# Run detection

result = detector.detect(request_payload)
print(result)

This pattern mirrors how ADRDetector internally resolves and instantiates detectors, giving you full control over initialization parameters.

Key Source Files for Understanding the Implementation

File Path Purpose
Detection/guardrail/base_detector.py Abstract BaseDetector class defining the required interface
Detection/guardrail/llamafirewall_agent/llamafirewall_baseline.py Concrete LlamaFirewall detector implementation
Detection/config_detector.yaml Registry mapping names to detector classes
Detection/main_detector.py CLI entry point handling argument parsing and detector resolution

When to Use LlamaFirewall vs. Other Detectors

LlamaFirewall serves as an alternative detector when you need:

  • On-premise inference: Runs locally without external API calls
  • Custom model weights: Uses your fine-tuned LlamaFirewall checkpoint
  • Reduced latency: Eliminates network round-trips to cloud services
  • Cost optimization: Avoids per-query pricing of commercial APIs

The trade-off is infrastructure complexity—you must host and serve the LlamaFirewall model yourself.

Summary

  • LlamaFirewall implements BaseDetector: Full compatibility with the ADR framework's guardrail system
  • Zero-code swapping: Change detectors via --detector llamafirewall or YAML configuration
  • Registry-driven architecture: config_detector.yaml maps names to classes; main_detector.py handles resolution
  • Production-ready: Ships in the official uber/ADR repository with documented implementation paths

Frequently Asked Questions

How do I switch from the OpenAI detector to LlamaFirewall?

Change the --detector argument from openai to llamafirewall in your command, or update the detector field in your YAML configuration. The registry lookup in main_detector.py handles the rest automatically.

What methods must LlamaFirewall implement to work as an ADR detector?

Per base_detector.py, it must provide detect(), typically load(), and follow initialization signatures expected by the registry. The existing llamafirewall_baseline.py demonstrates the complete implementation.

Can I use LlamaFirewall alongside other detectors simultaneously?

The current main_detector.py design loads one detector per invocation. For ensemble or parallel detection, you would instantiate multiple detector classes programmatically as shown in the programmatic usage example.

Where is LlamaFirewall registered as an available detector?

The registration entry is in Detection/config_detector.yaml, which maps the string name "llamafirewall" to the import path Detection.guardrail.llamafirewall_agent.llamafirewall_baseline.LlamaFirewallBaseline.

Have a question about this repo?

These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:

Share the following with your agent to get started:
curl -s "https://instagit.com/install.md"

Works with
Claude Codex Cursor VS Code OpenClaw Any MCP Client

Maintain an open-source project? Get it listed too →