LongPIBench: A Long-Context Benchmark for Prompt Injection
公开更多
研究结论
0 / 5 条结论已通过验证
其余仍在验证中
关键指标论文报告值 → 复现观测值 · 点击行展开详情
On long-context document tasks, heuristic prompt-injection attacks substantially increase attack success rate over no-attack baselines, and Authority spoof is generally the strongest listed heuristic.证据不足0/1 项指标获得支持 · 1 项已有评估报告 1 fraction1 fraction
报告
1 fraction
观测
1 fraction
偏差
±0 fraction
现有执行证据不足以确认或质疑这项论文结论。 · 这不构成对论文结论的反驳,只表示目前的证据既不能确认,也不能否定它。
attack_success_rate · 证据不足
报告: 1 fraction
观测: 1 fraction
The observed value is recorded as directional evidence, but approximate reconstruction fidelity cannot establish a strict Match against the paper
Prevention-based defenses that perform well on short-context benchmarks retain substantial attack success on the paper's long-context synthetic benchmark, although PromptLocate and MetaSecAlign 8B are lower than several simpler defenses on some tasks.实验受阻,详见具体原因报告 1 fraction
报告
1 fraction
观测
—
The closest executable candidate is a public or independently coded prevention defense on newly generated long documents. It would replace the report-defining MetaSecAlign 8B checkpoint, pipeline, and synthetic panel, making the result proxy evidence rather than the reported ASR; the fixed paper provides none of those executable assets.
attack_success_rate · 尚未评估
报告: 1 fraction
The paper reports that detection-based defenses exhibit an extreme false-positive/false-negative trade-off on long-context inputs, with some methods flagging benign inputs and others missing attacks.实验受阻,详见具体原因报告 0.43 fraction
报告
0.43 fraction
观测
—
The closest executable candidate is a public detector on newly generated matched benign and attacked panels with paper-like segment sizes. It would replace the named detector implementations, checkpoints, exact panel, and unspecified segmentation aggregation, producing proxy detector behavior rather than the reported comparison; those inputs are unavailable.
false_positive_rate · 尚未评估
报告: 0.43 fraction
The paper reports that GCG and its universal variant achieve high attack success across all four task suites and outperform heuristic attacks on several tasks.实验受阻,详见具体原因报告 1 fraction
报告
1 fraction
观测
—
The closest executable candidate is an independent GCG loop against a public checkpoint on newly generated long documents. It would substitute the paper's target model, generated panel, GCG defaults, and attacker target construction; those material changes can alter ASR, so the candidate is proxy evidence rather than a comparable reconstruction and cannot satisfy this measurement.
attack_success_rate · 尚未评估
报告: 1 fraction
其余结论1
The benchmark evaluates static document-centric workflows in which the full document is supplied in one inference call and does not cover dynamic multi-step agentic workflows or the full range of automated attacks.论文自述边界
This is an explicitly stated limitation rather than an independent empirical measurement.