LongPIBench: A Long-Context Benchmark for Prompt Injection

公开
作者:Yupei LiuYuqi JiaNeil Zhenqiang GongJinyuan Jia
更多
复制仓库链接

研究结论

0 / 5 条结论已通过验证

其余仍在验证中

关键指标论文报告值 → 复现观测值 · 点击行展开详情

On long-context document tasks, heuristic prompt-injection attacks substantially increase attack success rate over no-attack baselines, and Authority spoof is generally the strongest listed heuristic.证据不足0/1 项指标获得支持 · 1 项已有评估报告 1 fraction1 fraction

报告

1 fraction

观测

1 fraction

偏差

±0 fraction

现有执行证据不足以确认或质疑这项论文结论。 · 这不构成对论文结论的反驳,只表示目前的证据既不能确认,也不能否定它。

attack_success_rate · 证据不足

报告: 1 fraction

观测: 1 fraction

The observed value is recorded as directional evidence, but approximate reconstruction fidelity cannot establish a strict Match against the paper

打开 Claim 详情
Prevention-based defenses that perform well on short-context benchmarks retain substantial attack success on the paper's long-context synthetic benchmark, although PromptLocate and MetaSecAlign 8B are lower than several simpler defenses on some tasks.实验受阻,详见具体原因报告 1 fraction

报告

1 fraction

观测

The closest executable candidate is a public or independently coded prevention defense on newly generated long documents. It would replace the report-defining MetaSecAlign 8B checkpoint, pipeline, and synthetic panel, making the result proxy evidence rather than the reported ASR; the fixed paper provides none of those executable assets.

attack_success_rate · 尚未评估

报告: 1 fraction

The paper reports that detection-based defenses exhibit an extreme false-positive/false-negative trade-off on long-context inputs, with some methods flagging benign inputs and others missing attacks.实验受阻,详见具体原因报告 0.43 fraction

报告

0.43 fraction

观测

The closest executable candidate is a public detector on newly generated matched benign and attacked panels with paper-like segment sizes. It would replace the named detector implementations, checkpoints, exact panel, and unspecified segmentation aggregation, producing proxy detector behavior rather than the reported comparison; those inputs are unavailable.

false_positive_rate · 尚未评估

报告: 0.43 fraction

The paper reports that GCG and its universal variant achieve high attack success across all four task suites and outperform heuristic attacks on several tasks.实验受阻,详见具体原因报告 1 fraction

报告

1 fraction

观测

The closest executable candidate is an independent GCG loop against a public checkpoint on newly generated long documents. It would substitute the paper's target model, generated panel, GCG defaults, and attacker target construction; those material changes can alter ASR, so the candidate is proxy evidence rather than a comparable reconstruction and cannot satisfy this measurement.

attack_success_rate · 尚未评估

报告: 1 fraction

其余结论1
The benchmark evaluates static document-centric workflows in which the full document is supplied in one inference call and does not cover dynamic multi-step agentic workflows or the full range of automated attacks.论文自述边界

This is an explicitly stated limitation rather than an independent empirical measurement.