To be specific, our "byzantine" faults are limited to very specific types of behavior: running multiple copies of the same validator on different nodes, and modifying on-disk state of the validator. We make no changes to the validator source, don't inject arbitrary messages, don't attempt to invalidate already signed blocks, etc etc.
It means we simply give two different nodes the same signing key and get them to sign conflicting proposals and votes. A more complicated Byzantine fault would take into consideration the structure of the underlying protocol to try to thwart consensus safety in a more intelligent way.