A benchmark of 104,728 synthetic-but-realistic user prompts for measuring how PII detection
degrades under inference-time adversarial attack. Every prompt carries character-accurate span
labels, so the same corpus supports both document-level (was anything flagged?) and span-level
(was the right text flagged?) evaluation.
All PII in this dataset is synthetic. Identifiers are generated by Faker via Microsoft
Presidio; no value refers to a real… See the full description on the dataset page:
https://huggingface.co/datasets/roei-ar/AdvPIIBench.