{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2024:Q6ECP4YVUIWFQSYOEDIDCJ7EBR","short_pith_number":"pith:Q6ECP4YV","schema_version":"1.0","canonical_sha256":"878827f315a22c584b0e20d03127e40c7f9a2d051032af56149dd27152c7d5f2","source":{"kind":"arxiv","id":"2412.13426","version":3},"attestation_state":"computed","paper":{"title":"PromptKeeper: Safeguarding System Prompts for LLMs","license":"http://creativecommons.org/licenses/by/4.0/","headline":"","cross_cats":["cs.AI"],"primary_cat":"cs.CR","authors_text":"Guoliang He, Zhifeng Jiang, Zhihua Jin","submitted_at":"2024-12-18T01:43:25Z","abstract_excerpt":"System prompts are widely used to guide the outputs of large language models (LLMs). These prompts often contain business logic and sensitive information, making their protection essential. However, adversarial and even regular user queries can exploit LLM vulnerabilities to expose these hidden prompts. To address this issue, we propose PromptKeeper, a defense mechanism designed to safeguard system prompts by tackling two core challenges: reliably detecting leakage and mitigating side-channel vulnerabilities when leakage occurs. By framing detection as a hypothesis-testing problem, PromptKeepe"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2412.13426","kind":"arxiv","version":3},"metadata":{"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2024-12-18T01:43:25Z","cross_cats_sorted":["cs.AI"],"title_canon_sha256":"56d969aadebbe5f54581aee6cce95497a289fb27face8320f5f2ebc75a1ed378","abstract_canon_sha256":"1f02be65024a53168cefc5e7af0dee59c6b0cdb9bd5a1b8f35e38a17b5cdbf67"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T11:59:56.071640Z","signature_b64":"6tNpbd/p7HqlCGWEauUVlwpepbaN/DEWfz/Ne+Dkn1Z6pAWFYO8TnPKNuxcGawQ1Gqje1XIvcI6vbE9Nl3D5Cw==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"878827f315a22c584b0e20d03127e40c7f9a2d051032af56149dd27152c7d5f2","last_reissued_at":"2026-07-05T11:59:56.071234Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T11:59:56.071234Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"PromptKeeper: Safeguarding System Prompts for LLMs","license":"http://creativecommons.org/licenses/by/4.0/","headline":"","cross_cats":["cs.AI"],"primary_cat":"cs.CR","authors_text":"Guoliang He, Zhifeng Jiang, Zhihua Jin","submitted_at":"2024-12-18T01:43:25Z","abstract_excerpt":"System prompts are widely used to guide the outputs of large language models (LLMs). These prompts often contain business logic and sensitive information, making their protection essential. However, adversarial and even regular user queries can exploit LLM vulnerabilities to expose these hidden prompts. To address this issue, we propose PromptKeeper, a defense mechanism designed to safeguard system prompts by tackling two core challenges: reliably detecting leakage and mitigating side-channel vulnerabilities when leakage occurs. By framing detection as a hypothesis-testing problem, PromptKeepe"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2412.13426","kind":"arxiv","version":3},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2412.13426/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2412.13426","created_at":"2026-07-05T11:59:56.071291+00:00"},{"alias_kind":"arxiv_version","alias_value":"2412.13426v3","created_at":"2026-07-05T11:59:56.071291+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2412.13426","created_at":"2026-07-05T11:59:56.071291+00:00"},{"alias_kind":"pith_short_12","alias_value":"Q6ECP4YVUIWF","created_at":"2026-07-05T11:59:56.071291+00:00"},{"alias_kind":"pith_short_16","alias_value":"Q6ECP4YVUIWFQSYO","created_at":"2026-07-05T11:59:56.071291+00:00"},{"alias_kind":"pith_short_8","alias_value":"Q6ECP4YV","created_at":"2026-07-05T11:59:56.071291+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":4,"internal_anchor_count":0,"sample":[{"citing_arxiv_id":"2606.18673","citing_title":"Understanding and Mitigating Prompt Leaking Attacks in Real-World LLM-Based Applications","ref_index":40,"is_internal_anchor":false},{"citing_arxiv_id":"2605.05974","citing_title":"PragLocker: Protecting Agent Intellectual Property in Untrusted Deployments via Non-Portable Prompts","ref_index":86,"is_internal_anchor":false},{"citing_arxiv_id":"2604.27202","citing_title":"Indirect Prompt Injection in the Wild: An Empirical Study of Prevalence, Techniques, and Objectives","ref_index":55,"is_internal_anchor":false},{"citing_arxiv_id":"2605.05974","citing_title":"PragLocker: Protecting Agent Intellectual Property in Untrusted Deployments via Non-Portable Prompts","ref_index":86,"is_internal_anchor":false}]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/Q6ECP4YVUIWFQSYOEDIDCJ7EBR","json":"https://pith.science/pith/Q6ECP4YVUIWFQSYOEDIDCJ7EBR.json","graph_json":"https://pith.science/api/pith-number/Q6ECP4YVUIWFQSYOEDIDCJ7EBR/graph.json","events_json":"https://pith.science/api/pith-number/Q6ECP4YVUIWFQSYOEDIDCJ7EBR/events.json","paper":"https://pith.science/paper/Q6ECP4YV"},"agent_actions":{"view_html":"https://pith.science/pith/Q6ECP4YVUIWFQSYOEDIDCJ7EBR","download_json":"https://pith.science/pith/Q6ECP4YVUIWFQSYOEDIDCJ7EBR.json","view_paper":"https://pith.science/paper/Q6ECP4YV","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2412.13426&json=true","fetch_graph":"https://pith.science/api/pith-number/Q6ECP4YVUIWFQSYOEDIDCJ7EBR/graph.json","fetch_events":"https://pith.science/api/pith-number/Q6ECP4YVUIWFQSYOEDIDCJ7EBR/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/Q6ECP4YVUIWFQSYOEDIDCJ7EBR/action/timestamp_anchor","attest_storage":"https://pith.science/pith/Q6ECP4YVUIWFQSYOEDIDCJ7EBR/action/storage_attestation","attest_author":"https://pith.science/pith/Q6ECP4YVUIWFQSYOEDIDCJ7EBR/action/author_attestation","sign_citation":"https://pith.science/pith/Q6ECP4YVUIWFQSYOEDIDCJ7EBR/action/citation_signature","submit_replication":"https://pith.science/pith/Q6ECP4YVUIWFQSYOEDIDCJ7EBR/action/replication_record"}},"created_at":"2026-07-05T11:59:56.071291+00:00","updated_at":"2026-07-05T11:59:56.071291+00:00"}