כתבה
arXiv cs.CL ·
PARSE: תיקון-מודע-למקור של חיפוש-מודע-לפריט-למקור לסוכני LLM עסקיים
PARSE: Provenance-Aware Retrieval Sanitization for Professional Domain LLM Agents
מערכת של תיקון-מודע-למקור של חיפוש-מודע-לפריט-למקור לסוכני LLM עסקיים. המערכת נבחנה על 122 תפקידים ב-5 תחומים עסקיים. PARSE הצליחה לצמצם את קצב ההתקפות ב-39%.
תקציר מקורי באנגליתarXiv:2606.17467v3 Announce Type: replace-cross Abstract: Prompt injection defenses evaluated on synthetic benchmarks do not generalize to real enterprise documents, which are longer, denser, and interleave legitimate authority language with factual content. We demonstrate this gap with a benchmark of 122 tasks across five professional domains (financial, legal, medical, scientific, DevOps) built on real retrieved documents -- actual SEC filings, Federal Register rules, PubMed abstracts, arXiv papers, and GitHub postmortems -- paired with LLM-generated tasks and camouflaged payloads that were not human-validated. Paraphrasing, the strongest defense on synthetic benchmarks, shows no statistically significant attack success rate reduction on real documents (p=0.500) while degrading utility f
קרא במקור המקורי
arxiv.org
פתח כתבה מקורית