Attention is All You Need to Defend Against Indirect Prompt Injection Attacks in LLMs
Yinan Zhong, Qianhao Miao, Yanjiao Chen, Jiangyi Deng, Yushi Cheng, Wenyuan Xu
TL;DR
Rennervate tackles Indirect Prompt Injection in LLM-driven applications by introducing token-level detection that harnesses attention features, combined with a 2-step attentive pooling mechanism for robust generalization. It couples this detector with an injection identifier and a sanitization module to remove injected tokens while preserving benign instruction functionality. The authors validate Rennervate across five diverse LLMs and a new large-scale FIPI dataset, demonstrating superior detection and sanitization performance, transferability to unseen attacks, and resilience to adaptive adversaries. The work also provides extensive ablations and hyperparameter analyses, and discusses practical deployment considerations and limitations. Overall, Rennervate offers a compact, non-intrusive defense that advances robust IPI protection for real-world, LLM-integrated systems, with open questions around recovery from injected-task-specific content and multi-modal threats.
Abstract
Large Language Models (LLMs) have been integrated into many applications (e.g., web agents) to perform more sophisticated tasks. However, LLM-empowered applications are vulnerable to Indirect Prompt Injection (IPI) attacks, where instructions are injected via untrustworthy external data sources. This paper presents Rennervate, a defense framework to detect and prevent IPI attacks. Rennervate leverages attention features to detect the covert injection at a fine-grained token level, enabling precise sanitization that neutralizes IPI attacks while maintaining LLM functionalities. Specifically, the token-level detector is materialized with a 2-step attentive pooling mechanism, which aggregates attention heads and response tokens for IPI detection and sanitization. Moreover, we establish a fine-grained IPI dataset, FIPI, to be open-sourced to support further research. Extensive experiments verify that Rennervate outperforms 15 commercial and academic IPI defense methods, achieving high precision on 5 LLMs and 6 datasets. We also demonstrate that Rennervate is transferable to unseen attacks and robust against adaptive adversaries.
