Chen, Piet, Sitawarin and Wagner propose structured queries, in which a secure front-end separates the trusted prompt from untrusted data and a model fine-tuned to ignore instructions appearing in the data portion. The paper reports much better resistance to prompt injection with little utility loss; it appeared at USENIX Security 2025.
Why it matters
It is a training-based instruction and data separation defense that later adaptive-attack work targets.
Key facts
As stated in the sources, with where to find them.
- The authors report significantly improved resistance to prompt injection with little or no utility impact from structured instruction tuning.Abstract
Findings that cite this record
Key questions this bears on
- Can prompt injection against AI agents be reliably defended?Not reliably. Defenses reduce injection but none has eliminated it; limiting what untrusted input can trigger is the most defensible approach.
Sources
Related records
Oct 7, 2024
Mar 20, 2024
Jan 4, 2024
Oct 10, 2025
Apr 19, 2024
Jul 28, 2025