Scope: what this does not show
One design (CaMeL) on AgentDojo; does not stop manipulation within permitted data flows, and has not been independently attacked at scale.
Revalidate: Older than its half-life with no newer evidence. May no longer hold.
Evidence
Mar 24, 2025
Google DeepMind's CaMeL defeats prompt injections by design with capability-based control and data flow
Solved 77% of AgentDojo tasks with provable security; about 7 points below an undefended agent.
How it relates to other findings
ReportedCorroboratedQualifiedContestedSupersededRevalidate· node size = evidence records · columns group by topic
Select a finding to see how it relates to others. Arrows point from the newer finding to the one it supports, qualifies, contests, or supersedes.
- Limiting what untrusted input can cause an agent to do gives injection resistance that does not depend on the model resisting. supports this findingCaMeL is one implementation of this principle.
Status history
- 2025-03-24ReportedGoogle DeepMind introduces CaMeL. · record
- 2026-09-26RevalidateComputed: 551 days since the last evidence, past the 540-day half-life.