{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2025:Z2PQDCC3K6LKLOH43RBYPZBV54","short_pith_number":"pith:Z2PQDCC3","schema_version":"1.0","canonical_sha256":"ce9f01885b5796a5b8fcdc4387e435ef17bc0cf82ac942608715c0644bd18099","source":{"kind":"arxiv","id":"2507.07974","version":2},"attestation_state":"computed","paper":{"title":"Defending Against Prompt Injection With a Few DefensiveTokens","license":"http://creativecommons.org/licenses/by/4.0/","headline":"","cross_cats":[],"primary_cat":"cs.CR","authors_text":"Chawin Sitawarin, David Wagner, Nicholas Carlini, Sizhe Chen, Yizhu Wang","submitted_at":"2025-07-10T17:51:05Z","abstract_excerpt":"When large language model (LLM) systems interact with external data to perform complex tasks, a new attack, namely prompt injection, becomes a significant threat. By injecting instructions into the data accessed by the system, the attacker is able to override the initial user task with an arbitrary task directed by the attacker. To secure the system, test-time defenses, e.g., defensive prompting, have been proposed for system developers to attain security only when needed in a flexible manner. However, they are much less effective than training-time defenses that change the model parameters. M"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2507.07974","kind":"arxiv","version":2},"metadata":{"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2025-07-10T17:51:05Z","cross_cats_sorted":[],"title_canon_sha256":"c77e27cd3b1dc288dad9c9b1b2e11955d938317ad044b3ea8118d174e0c0f9be","abstract_canon_sha256":"1d5c3288fb94568e68165bb1479565549cbab750265cb76857d14197ac0cc3af"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T11:58:32.719150Z","signature_b64":"JF0tUaspBL/AJRuzTCZq1WKiLK6PK6ryiEyBcjXOm2H0yhGXnYlTU4i5UwwNrnp5qh5p6tMgwXGCVrcgOlGrBQ==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"ce9f01885b5796a5b8fcdc4387e435ef17bc0cf82ac942608715c0644bd18099","last_reissued_at":"2026-07-05T11:58:32.718651Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T11:58:32.718651Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"Defending Against Prompt Injection With a Few DefensiveTokens","license":"http://creativecommons.org/licenses/by/4.0/","headline":"","cross_cats":[],"primary_cat":"cs.CR","authors_text":"Chawin Sitawarin, David Wagner, Nicholas Carlini, Sizhe Chen, Yizhu Wang","submitted_at":"2025-07-10T17:51:05Z","abstract_excerpt":"When large language model (LLM) systems interact with external data to perform complex tasks, a new attack, namely prompt injection, becomes a significant threat. By injecting instructions into the data accessed by the system, the attacker is able to override the initial user task with an arbitrary task directed by the attacker. To secure the system, test-time defenses, e.g., defensive prompting, have been proposed for system developers to attain security only when needed in a flexible manner. However, they are much less effective than training-time defenses that change the model parameters. M"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2507.07974","kind":"arxiv","version":2},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2507.07974/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2507.07974","created_at":"2026-07-05T11:58:32.718712+00:00"},{"alias_kind":"arxiv_version","alias_value":"2507.07974v2","created_at":"2026-07-05T11:58:32.718712+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2507.07974","created_at":"2026-07-05T11:58:32.718712+00:00"},{"alias_kind":"pith_short_12","alias_value":"Z2PQDCC3K6LK","created_at":"2026-07-05T11:58:32.718712+00:00"},{"alias_kind":"pith_short_16","alias_value":"Z2PQDCC3K6LKLOH4","created_at":"2026-07-05T11:58:32.718712+00:00"},{"alias_kind":"pith_short_8","alias_value":"Z2PQDCC3","created_at":"2026-07-05T11:58:32.718712+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":5,"internal_anchor_count":0,"sample":[{"citing_arxiv_id":"2606.18673","citing_title":"Understanding and Mitigating Prompt Leaking Attacks in Real-World LLM-Based Applications","ref_index":31,"is_internal_anchor":false},{"citing_arxiv_id":"2605.18991","citing_title":"Agent Security is a Systems Problem","ref_index":9,"is_internal_anchor":false},{"citing_arxiv_id":"2605.18991","citing_title":"Agent Security is a Systems Problem","ref_index":9,"is_internal_anchor":false},{"citing_arxiv_id":"2604.24118","citing_title":"AgentVisor: Defending LLM Agents Against Prompt Injection via Semantic Virtualization","ref_index":1,"is_internal_anchor":false},{"citing_arxiv_id":"2605.00741","citing_title":"Self-Adaptive Multi-Agent LLM-Based Security Pattern Selection for IoT Systems","ref_index":40,"is_internal_anchor":false}]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/Z2PQDCC3K6LKLOH43RBYPZBV54","json":"https://pith.science/pith/Z2PQDCC3K6LKLOH43RBYPZBV54.json","graph_json":"https://pith.science/api/pith-number/Z2PQDCC3K6LKLOH43RBYPZBV54/graph.json","events_json":"https://pith.science/api/pith-number/Z2PQDCC3K6LKLOH43RBYPZBV54/events.json","paper":"https://pith.science/paper/Z2PQDCC3"},"agent_actions":{"view_html":"https://pith.science/pith/Z2PQDCC3K6LKLOH43RBYPZBV54","download_json":"https://pith.science/pith/Z2PQDCC3K6LKLOH43RBYPZBV54.json","view_paper":"https://pith.science/paper/Z2PQDCC3","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2507.07974&json=true","fetch_graph":"https://pith.science/api/pith-number/Z2PQDCC3K6LKLOH43RBYPZBV54/graph.json","fetch_events":"https://pith.science/api/pith-number/Z2PQDCC3K6LKLOH43RBYPZBV54/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/Z2PQDCC3K6LKLOH43RBYPZBV54/action/timestamp_anchor","attest_storage":"https://pith.science/pith/Z2PQDCC3K6LKLOH43RBYPZBV54/action/storage_attestation","attest_author":"https://pith.science/pith/Z2PQDCC3K6LKLOH43RBYPZBV54/action/author_attestation","sign_citation":"https://pith.science/pith/Z2PQDCC3K6LKLOH43RBYPZBV54/action/citation_signature","submit_replication":"https://pith.science/pith/Z2PQDCC3K6LKLOH43RBYPZBV54/action/replication_record"}},"created_at":"2026-07-05T11:58:32.718712+00:00","updated_at":"2026-07-05T11:58:32.718712+00:00"}