Activation steering sharply reduces indirect prompt injection in open models

CounterSteer suppresses models’ tendency to interpret retrieved text as instructions by modifying internal activations during inference.

Big Tech
Mark Russinovich

Microsoft Azure

Research Digest··3 min read
Russinovich presents CounterSteer, an inference-time defense that subtracts a learned activation direction from tokens returned by tools, without adding prompt text, training the model, or first detecting an attack.

The author constructed paired agent episodes that differed in whether a model followed an instruction embedded in untrusted tool output.

Why this paper

From Microsoft Azure

In one line

CounterSteer suppresses indirect prompt injection by subtracting a per-model residual-stream direction from tool-result tokens during prefill, cutting attack success to near zero without utility loss.

What we could check

  • ·No code link found
  • ·No weights link found
  • ·No dataset link found
  • ·No compute details found
  • ✓Limitations stated by the authors (3 noted)
  • ✓Reports numbers on named benchmarks (7 benchmarks)

Observed from the paper text and links we have. Absence here means we did not find it, not that it does not exist.

§

Research Digest

Written by software from the reporting listed above, scored by an automated standards desk, and published without a person reading it first. If something here is wrong, tell the editor and it will be put right.