Pith. sign in

REVIEW 2 cited by

CAPTURE: Context-Aware Prompt Injection Testing and Robustness Enhancement

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 2505.12368 v2 pith:2SI2JNX2 submitted 2025-05-18 cs.CL cs.AI

CAPTURE: Context-Aware Prompt Injection Testing and Robustness Enhancement

classification cs.CL cs.AI
keywords context-awarefalseinjectionpromptmodelsattackbenchmarkscapture
verification ladder T0 review T1 audit T2 compute T3 formal T4 reserved
0 comments
read the original abstract

Prompt injection remains a major security risk for large language models. However, the efficacy of existing guardrail models in context-aware settings remains underexplored, as they often rely on static attack benchmarks. Additionally, they have over-defense tendencies. We introduce CAPTURE, a novel context-aware benchmark assessing both attack detection and over-defense tendencies with minimal in-domain examples. Our experiments reveal that current prompt injection guardrail models suffer from high false negatives in adversarial cases and excessive false positives in benign scenarios, highlighting critical limitations. To demonstrate our framework's utility, we train CaptureGuard on our generated data. This new model drastically reduces both false negative and false positive rates on our context-aware datasets while also generalizing effectively to external benchmarks, establishing a path toward more robust and practical prompt injection defenses.

discussion (0)

Sign in with ORCID, Apple, or X to comment. Anyone can read and Pith papers without signing in.

Forward citations

Cited by 2 Pith papers

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score.

  1. CrackedPDFs: A Controlled Benchmark for Hidden Prompt Injection in PDFs

    cs.AI 2026-07 conditional novelty 6.0

    A 29,322-PDF controlled benchmark shows that a hybrid structural-plus-text detector finds hidden PDF prompt injections under paired evaluation (0.960 F1; 100% pair ranking), while text-only baselines fail.

  2. CrackedPDFs: A Controlled Benchmark for Hidden Prompt Injection in PDFs

    cs.AI 2026-07 conditional novelty 5.0

    A document-aware hybrid detector that inspects PDF structure before text flattening outperforms text-only guardrails and structural-only models on a new 29,322-file controlled hidden-prompt-injection benchmark.