{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2024:QHOLJPVLT2AHZ5X645MHG74DHQ","short_pith_number":"pith:QHOLJPVL","schema_version":"1.0","canonical_sha256":"81dcb4beab9e807cf6fee758737f833c2cb0653bf356f5850694e305f25b8f7a","source":{"kind":"arxiv","id":"2402.06363","version":2},"attestation_state":"computed","paper":{"title":"StruQ: Defending Against Prompt Injection with Structured Queries","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":[],"primary_cat":"cs.CR","authors_text":"Chawin Sitawarin, David Wagner, Julien Piet, Sizhe Chen","submitted_at":"2024-02-09T12:15:51Z","abstract_excerpt":"Recent advances in Large Language Models (LLMs) enable exciting LLM-integrated applications, which perform text-based tasks by utilizing their advanced language understanding capabilities. However, as LLMs have improved, so have the attacks against them. Prompt injection attacks are an important threat: they trick the model into deviating from the original application's instructions and instead follow user directives. These attacks rely on the LLM's ability to follow instructions and inability to separate prompts and user data. We introduce structured queries, a general approach to tackle this"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2402.06363","kind":"arxiv","version":2},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2024-02-09T12:15:51Z","cross_cats_sorted":[],"title_canon_sha256":"f3b2590dec92c3f08becba30f8b1d8ae343ab5871f021c5d9f89752049e79693","abstract_canon_sha256":"de66f95ea93c6469830ac8390ed1ca13ee6a7a1e744fbda09fe18edb4e9b72c7"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T09:11:46.621747Z","signature_b64":"l9N4UyLp6Zauzl8p2oxfn9/f2OOoPuEfFjV/ljlPCm1/kBeooF0CfIe4pQ4gBDRIQUk1XKcDAZ52QZdZPLhmDQ==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"81dcb4beab9e807cf6fee758737f833c2cb0653bf356f5850694e305f25b8f7a","last_reissued_at":"2026-07-05T09:11:46.621176Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T09:11:46.621176Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"StruQ: Defending Against Prompt Injection with Structured Queries","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":[],"primary_cat":"cs.CR","authors_text":"Chawin Sitawarin, David Wagner, Julien Piet, Sizhe Chen","submitted_at":"2024-02-09T12:15:51Z","abstract_excerpt":"Recent advances in Large Language Models (LLMs) enable exciting LLM-integrated applications, which perform text-based tasks by utilizing their advanced language understanding capabilities. However, as LLMs have improved, so have the attacks against them. Prompt injection attacks are an important threat: they trick the model into deviating from the original application's instructions and instead follow user directives. These attacks rely on the LLM's ability to follow instructions and inability to separate prompts and user data. We introduce structured queries, a general approach to tackle this"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2402.06363","kind":"arxiv","version":2},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2402.06363/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2402.06363","created_at":"2026-07-05T09:11:46.621247+00:00"},{"alias_kind":"arxiv_version","alias_value":"2402.06363v2","created_at":"2026-07-05T09:11:46.621247+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2402.06363","created_at":"2026-07-05T09:11:46.621247+00:00"},{"alias_kind":"pith_short_12","alias_value":"QHOLJPVLT2AH","created_at":"2026-07-05T09:11:46.621247+00:00"},{"alias_kind":"pith_short_16","alias_value":"QHOLJPVLT2AHZ5X6","created_at":"2026-07-05T09:11:46.621247+00:00"},{"alias_kind":"pith_short_8","alias_value":"QHOLJPVL","created_at":"2026-07-05T09:11:46.621247+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":32,"internal_anchor_count":2,"sample":[{"citing_arxiv_id":"2607.08147","citing_title":"Prismata: Confining Cross-Site Prompt Injection in Web Agents","ref_index":10,"is_internal_anchor":true},{"citing_arxiv_id":"2607.08395","citing_title":"Token-Flow Firewall: Semantic Runtime Auditing for Persistent AI Agents","ref_index":16,"is_internal_anchor":true},{"citing_arxiv_id":"2606.26627","citing_title":"Agents That Know Too Much: A Data-Centric Survey of Privacy in LLM Agents","ref_index":21,"is_internal_anchor":false},{"citing_arxiv_id":"2606.26479","citing_title":"Adaptive Evaluation of Out-of-Band Defenses Against Prompt Injection in LLM Agents","ref_index":4,"is_internal_anchor":false},{"citing_arxiv_id":"2606.17573","citing_title":"Cordon: Semantic Transactions for Tool-Using LLM Agents","ref_index":12,"is_internal_anchor":false},{"citing_arxiv_id":"2606.18120","citing_title":"Structural Role Injection in Handlebars-Templated LLM Prompts: Triple-Brace Interpolation, Delimiter Family, and the Limits of HTML Auto-Escaping","ref_index":13,"is_internal_anchor":false},{"citing_arxiv_id":"2606.15057","citing_title":"AutoDojo: Adaptive Black-Box Attacks Reveal the Limits of IPI Defenses and Task-Specification Effects in LLM Agents","ref_index":7,"is_internal_anchor":false},{"citing_arxiv_id":"2606.04109","citing_title":"Discourse-Role Labels as Presentation-Time Variables for Context Use in Language Models","ref_index":2,"is_internal_anchor":false},{"citing_arxiv_id":"2606.02668","citing_title":"What You Approve Is What Executes: Consent Integrity for Black-Box LLM Agents","ref_index":21,"is_internal_anchor":false},{"citing_arxiv_id":"2606.32002","citing_title":"Self-Study Reconsidered: The Hidden Fragility of Learning from Self-Generated QA","ref_index":5,"is_internal_anchor":false},{"citing_arxiv_id":"2606.30783","citing_title":"Security--Fidelity Tradeoffs: The Hidden Cost of Prompt Injection Defense","ref_index":41,"is_internal_anchor":false},{"citing_arxiv_id":"2606.30383","citing_title":"Whose Side Is Your Agent On? Multi-Party Principal Loyalty in LLM Agents","ref_index":8,"is_internal_anchor":false},{"citing_arxiv_id":"2605.28467","citing_title":"Mitigating Adaptive Attacks against Reasoning Models with Activation Consistency Training","ref_index":3,"is_internal_anchor":false},{"citing_arxiv_id":"2605.30686","citing_title":"Depth-Dependent Indirect Prompt Injection in Tool-Calling ReAct Agents: Injection Depth, Payload Framing, and Turn-Budget Sensitivity","ref_index":8,"is_internal_anchor":false},{"citing_arxiv_id":"2605.31042","citing_title":"From Prompt Injection to Persistent Control: Defending Agentic Harness Against Trojan Backdoors","ref_index":4,"is_internal_anchor":false},{"citing_arxiv_id":"2504.20472","citing_title":"Robustness via Referencing: Defending against Prompt Injection Attacks by Referencing the Executed Instruction","ref_index":6,"is_internal_anchor":false},{"citing_arxiv_id":"2504.20984","citing_title":"ACE: A Security Architecture for LLM-Integrated App Systems","ref_index":20,"is_internal_anchor":false},{"citing_arxiv_id":"2605.18133","citing_title":"An Empirical Study of Privacy Leakage Chains via Prompt Injection in Black-Box Chatbot Environments","ref_index":25,"is_internal_anchor":false},{"citing_arxiv_id":"2605.16976","citing_title":"Securing LLM Agents Need Intent-to-Execution Integrity","ref_index":8,"is_internal_anchor":false},{"citing_arxiv_id":"2506.09067","citing_title":"Enhancing the Safety of Medical Vision-Language Models by Synthetic Demonstrations","ref_index":5,"is_internal_anchor":false},{"citing_arxiv_id":"2510.23883","citing_title":"Agentic AI Security: Threats, Defenses, Evaluation, and Open Challenges","ref_index":179,"is_internal_anchor":false},{"citing_arxiv_id":"2504.19793","citing_title":"Prompt Injection Attack to Tool Selection in LLM Agents","ref_index":23,"is_internal_anchor":false},{"citing_arxiv_id":"2410.07283","citing_title":"Prompt Infection: LLM-to-LLM Prompt Injection within Multi-Agent Systems","ref_index":53,"is_internal_anchor":false},{"citing_arxiv_id":"2410.07283","citing_title":"Prompt Infection: LLM-to-LLM Prompt Injection within Multi-Agent Systems","ref_index":6,"is_internal_anchor":false},{"citing_arxiv_id":"2603.27517","citing_title":"A Security Analysis of the OpenClaw AI Agent Framework","ref_index":18,"is_internal_anchor":false}]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/QHOLJPVLT2AHZ5X645MHG74DHQ","json":"https://pith.science/pith/QHOLJPVLT2AHZ5X645MHG74DHQ.json","graph_json":"https://pith.science/api/pith-number/QHOLJPVLT2AHZ5X645MHG74DHQ/graph.json","events_json":"https://pith.science/api/pith-number/QHOLJPVLT2AHZ5X645MHG74DHQ/events.json","paper":"https://pith.science/paper/QHOLJPVL"},"agent_actions":{"view_html":"https://pith.science/pith/QHOLJPVLT2AHZ5X645MHG74DHQ","download_json":"https://pith.science/pith/QHOLJPVLT2AHZ5X645MHG74DHQ.json","view_paper":"https://pith.science/paper/QHOLJPVL","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2402.06363&json=true","fetch_graph":"https://pith.science/api/pith-number/QHOLJPVLT2AHZ5X645MHG74DHQ/graph.json","fetch_events":"https://pith.science/api/pith-number/QHOLJPVLT2AHZ5X645MHG74DHQ/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/QHOLJPVLT2AHZ5X645MHG74DHQ/action/timestamp_anchor","attest_storage":"https://pith.science/pith/QHOLJPVLT2AHZ5X645MHG74DHQ/action/storage_attestation","attest_author":"https://pith.science/pith/QHOLJPVLT2AHZ5X645MHG74DHQ/action/author_attestation","sign_citation":"https://pith.science/pith/QHOLJPVLT2AHZ5X645MHG74DHQ/action/citation_signature","submit_replication":"https://pith.science/pith/QHOLJPVLT2AHZ5X645MHG74DHQ/action/replication_record"}},"created_at":"2026-07-05T09:11:46.621247+00:00","updated_at":"2026-07-05T09:11:46.621247+00:00"}