The author constructed paired agent episodes that differed in whether a model followed an instruction embedded in untrusted tool output.
Activation steering sharply reduces indirect prompt injection in open models
CounterSteer suppresses models’ tendency to interpret retrieved text as instructions by modifying internal activations during inference.
Big Tech
Mark Russinovich
Microsoft Azure
Research Digest··3 min read
Russinovich presents CounterSteer, an inference-time defense that subtracts a learned activation direction from tokens returned by tools, without adding prompt text, training the model, or first detecting an attack.
Why this paper
From Microsoft Azure
In one line
CounterSteer suppresses indirect prompt injection by subtracting a per-model residual-stream direction from tool-result tokens during prefill, cutting attack success to near zero without utility loss.
What we could check
- ·No code link found
- ·No weights link found
- ·No dataset link found
- ·No compute details found
- ✓Limitations stated by the authors (3 noted)
- ✓Reports numbers on named benchmarks (7 benchmarks)
Observed from the paper text and links we have. Absence here means we did not find it, not that it does not exist.
§