The authors developed SRFT, a framework that first injects adversarial instructions into clean expert agentic trajectories to create compromised trajectories.
Learning from failure enables LLM agents to resist prompt injection attacks
SRFT trains agents by contrasting hijacked and optimal actions, reducing attack success rates significantly on benchmarks.
Big Tech
Zixuan Wang · Hao Li · Fengyu Gao · G. Edward Suh · Yi Zeng · Yevgeniy Vorobeychik · +2 more
Johns Hopkins University · Washington University in St. Louis · University of Virginia · NVIDIA · Virginia Tech
Research Digest··2 min read
The authors propose Self-Reflection Fine-Tuning (SRFT), a training framework that exposes LLM agents to their own failure trajectories under prompt injection attacks and uses an expert model to generate self-reflection rationales.
Why this paper
From NVIDIA and 4 others · Part of Agent Security & Attacks, now 60 papers
In one line
Self-Reflection Fine-Tuning improves LLM agent robustness against prompt injection by learning from its own failure experiences.
What we could check
- ·No code link found
- ·No weights link found
- ·No dataset link found
- ·No compute details found
- ✓Limitations stated by the authors
- ✓Reports numbers on named benchmarks
Observed from the paper text and links we have. Absence here means we did not find it, not that it does not exist.
§