Learning from failure enables LLM agents to resist prompt injection attacks

SRFT trains agents by contrasting hijacked and optimal actions, reducing attack success rates significantly on benchmarks.

Big Tech
Zixuan Wang · Hao Li · Fengyu Gao · G. Edward Suh · Yi Zeng · Yevgeniy Vorobeychik · +2 more

Johns Hopkins University · Washington University in St. Louis · University of Virginia · NVIDIA · Virginia Tech

Research Digest··2 min read
The authors propose Self-Reflection Fine-Tuning (SRFT), a training framework that exposes LLM agents to their own failure trajectories under prompt injection attacks and uses an expert model to generate self-reflection rationales.

The authors developed SRFT, a framework that first injects adversarial instructions into clean expert agentic trajectories to create compromised trajectories.

Why this paper

From NVIDIA and 4 others · Part of Agent Security & Attacks, now 60 papers

In one line

Self-Reflection Fine-Tuning improves LLM agent robustness against prompt injection by learning from its own failure experiences.

What we could check

  • ·No code link found
  • ·No weights link found
  • ·No dataset link found
  • ·No compute details found
  • ✓Limitations stated by the authors
  • ✓Reports numbers on named benchmarks

Observed from the paper text and links we have. Absence here means we did not find it, not that it does not exist.

§

Research Digest

Written by software from the reporting listed above, scored by an automated standards desk, and published without a person reading it first. If something here is wrong, tell the editor and it will be put right.