Public articles linked to the same research event.
arXiv The work presents APEX, which shifts indirect prompt-injection defense from recognizing attack patterns to checking each proposed effect at the execution boundary: before untrusted execution it compiles the user's authorization into a contract, WRAP admits an effect only when the contract and runtime evidence reconstruct its authorization, and PLANT places probes on the contract's endorsed dependencies so unendorsed use of runtime information reveals itself before commitment; across six benchmarks and 13 baselines APEX reaches 0% attack success on five benchmarks and 0.56% on the sixth, and holds 0% under three adaptive attacks spanning all three capability-unit types.
The work presents APEX, which shifts indirect prompt-injection defense from recognizing attack patterns to checking each proposed effect at the execution boundary: before untrusted execution it compiles the user's authorization into a contract, WRAP admits an effect only when the contract and runtime evidence reconstruct its authorization, and PLANT places probes on the contract's endorsed dependencies so unendorsed use of runtime information reveals itself before commitment; across six benchmarks and 13 baselines APEX reaches 0% attack success on five benchmarks and 0.56% on the sixth, and holds 0% under three adaptive attacks spanning all three capability-unit types.
The work presents APEX, which shifts indirect prompt-injection defense from recognizing attack patterns to checking each proposed effect at the execution boundary: before untrusted execution it compiles the user's authorization into a contract, WRAP admits an effect only when the contract and runtime evidence reconstruct its authorization, and PLANT places probes on the contract's endorsed dependencies so unendorsed use of runtime information reveals itself before commitment; across six benchmarks and 13 baselines APEX reaches 0% attack success on five benchmarks and 0.56% on the sixth, and holds 0% under three adaptive attacks spanning all three capability-unit types.
The work presents APEX, which shifts indirect prompt-injection defense from recognizing attack patterns to checking each proposed effect at the execution boundary: before untrusted execution it compiles the user's authorization into a contract, WRAP admits an effect only when the contract and runtime evidence reconstruct its authorization, and PLANT places probes on the contract's endorsed dependencies so unendorsed use of runtime information reveals itself before commitment; across six benchmarks and 13 baselines APEX reaches 0% attack success on five benchmarks and 0.56% on the sixth, and holds 0% under three adaptive attacks spanning all three capability-unit types.