TensorX
返回文献探索

Paper · arXiv 2506.05446

Sentinel: SOTA model to protect against prompt injections

Dror Ivry, Oran Nahum

23 upvotesJune 5, 2025arXiv 预印本
AI 摘要

Sentinel, a detection model based on ModernBERT-large, effectively identifies prompt injection attacks with high accuracy and outperforms existing baselines.

ModernBERT-largeprompt injection attacksdataset curationtraining methodologyevaluationrole-playinginstruction hijackingbiased contenterror correctionreal-world misclassificationsF1-score

Abstract

Large Language Models (LLMs) are increasingly powerful but remain vulnerable to prompt injection attacks, where malicious inputs cause the model to deviate from its intended instructions. This paper introduces Sentinel, a novel detection model, qualifire/prompt-injection-sentinel, based on the \answerdotai/ModernBERT-large architecture. By leveraging ModernBERT's advanced features and fine-tuning on an extensive and diverse dataset comprising a few open-source and private collections, Sentinel achieves state-of-the-art performance. This dataset amalgamates varied attack types, from role-playing and instruction hijacking to attempts to generate biased content, alongside a broad spectrum of benign instructions, with private datasets specifically targeting nuanced error correction and real-world misclassifications. On a comprehensive, unseen internal test set, Sentinel demonstrates an average accuracy of 0.987 and an F1-score of 0.980. Furthermore, when evaluated on public benchmarks, it consistently outperforms strong baselines like protectai/deberta-v3-base-prompt-injection-v2. This work details Sentinel's architecture, its meticulous dataset curation, its training methodology, and a thorough evaluation, highlighting its superior detection capabilities.

北京市昌平区探索星信息技术及软件开发工作室

京ICP备2026059466号
Sentinel: SOTA model to protect against prompt injections | TensorX