Adversarial Test Corpora
Documented hostile input for regulated B2B formats — the cases that exploit a naive parser, validator, or AI agent, each with the safe expected behaviour. Free to use under CC0-1.0.
What this is
Valid test data proves the happy path. This corpus proves the hostile path: SQL and template injection, XML external entities, SSRF, entity expansion and other resource exhaustion, encoding attacks (homoglyphs, null bytes, bidi overrides), validation bypass, structural confusion, and prompt injection aimed at LLM agents that read the data.
Every case states the safe expected behaviour — reject, sanitise, or a specific error — so you can wire it into a unit test, a fuzzer, or a security review. Payloads are inert strings; this is a test corpus, not an exploit kit.
Corpora by format
| Format | Standard | Cases |
|---|---|---|
| IBAN Test Data | IBAN (ISO 13616) | 10 |
| VAT Test Data | VAT identification numbers | 10 |
| LEI Test Data | LEI (ISO 17442) | 10 |
| Container Number Test Data | Container number (ISO 6346) | 9 |
| IATA Air Waybill Test Data | Air waybill (IATA 600a) | 9 |
| GS1 GTIN Test Data | GS1 GTIN-14 / element string | 10 |
| UDI Test Data | UDI (GS1 / HIBCC / ICCBBA) | 9 |
| ANSI X12 Test Data | ANSI X12 837P | 10 |
| ISO 20022 Test Data | ISO 20022 pain.001.001.09 | 10 |
| Peppol BIS Test Data | Peppol BIS Billing 3.0 (UBL) | 10 |
| Factur-X / ZUGFeRD Test Data | Factur-X / ZUGFeRD (CII) | 10 |
| CBAM Test Data | EU CBAM goods data | 10 |
| EPCIS Test Data | GS1 EPCIS 2.0 JSON-LD | 9 |
How to use it
Pull the JSON for a format (/datasets/<format>/adversarial.json) and feed each payload to your parser. Assert that the result matches expected. Run it in CI next to the valid-data tests. See the guide for a worked example.