{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2026:IFMVKYUVDSBEUSCO6GW2YVUWJD","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"65072f82d2b9aac8b5d15547c412646aa1df0076e9143dc99c9a04008da479fd","cross_cats_sorted":["cs.CL"],"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2026-04-20T13:27:05Z","title_canon_sha256":"22ee573876f9c2fc734740f96a98698e5de844d0d13b190286e8cbf7950ed3d5"},"schema_version":"1.0","source":{"id":"2604.18248","kind":"arxiv","version":2}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2604.18248","created_at":"2026-05-20T00:05:44Z"},{"alias_kind":"arxiv_version","alias_value":"2604.18248v2","created_at":"2026-05-20T00:05:44Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2604.18248","created_at":"2026-05-20T00:05:44Z"},{"alias_kind":"pith_short_12","alias_value":"IFMVKYUVDSBE","created_at":"2026-05-20T00:05:44Z"},{"alias_kind":"pith_short_16","alias_value":"IFMVKYUVDSBEUSCO","created_at":"2026-05-20T00:05:44Z"},{"alias_kind":"pith_short_8","alias_value":"IFMVKYUV","created_at":"2026-05-20T00:05:44Z"}],"graph_snapshots":[{"event_id":"sha256:3b15afac842a01c0ef55887a7b8bcc18f5991f7b5293dd3cb0d244065226aa9f","target":"graph","created_at":"2026-05-20T00:05:44Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":4,"items":[{"attestation":"unclaimed","claim_id":"C1","kind":"strongest_claim","source":"verdict.strongest_claim","status":"machine_extracted","text":"The local-alignment detector lifts F1 on deepset from 0.033 to 0.378 with zero additional false positives. The stylometric detector adds 11.1 percentage points of F1 on an indirect-injection benchmark."},{"attestation":"unclaimed","claim_id":"C2","kind":"weakest_assumption","source":"verdict.weakest_assumption","status":"machine_extracted","text":"That mechanisms proven in their original domains (sequence alignment, fatigue analysis, etc.) will transfer to LLM prompt injection without being bypassed by adaptive adversaries or introducing new failure modes not captured in the six evaluation datasets."},{"attestation":"unclaimed","claim_id":"C3","kind":"one_line_summary","source":"verdict.one_line_summary","status":"machine_extracted","text":"Seven cross-domain techniques for prompt injection detection are proposed; three implemented versions raise F1 scores on multiple benchmarks while releasing all code and data."},{"attestation":"unclaimed","claim_id":"C4","kind":"headline","source":"verdict.pith_extraction.headline","status":"machine_extracted","text":"Seven techniques borrowed from bioinformatics, linguistics, and other fields detect prompt injections more effectively than regex or classifiers."}],"snapshot_sha256":"5edbd57420e8369a3029d3f92511a363f69a3491a599ef4f0edcca75e9892a32"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"integrity":{"available":true,"clean":true,"detectors_run":[],"endpoint":"/pith/2604.18248/integrity.json","findings":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938","summary":{"advisory":0,"by_detector":{},"critical":0,"informational":0}},"paper":{"abstract_excerpt":"Current open-source prompt-injection detectors converge on two architectural choices: regular-expression pattern matching and fine-tuned transformer classifiers. Both share failure modes that recent work has made concrete. Regular expressions miss paraphrased attacks. Fine-tuned classifiers are vulnerable to adaptive adversaries: a 2025 NAACL Findings study reported that eight published indirect-injection defenses were bypassed with greater than fifty percent attack success rates under adaptive attacks. This work proposes seven detection techniques that each port a specific mechanism from a di","authors_text":"Thamilvendhan Munirathinam","cross_cats":["cs.CL"],"headline":"Seven techniques borrowed from bioinformatics, linguistics, and other fields detect prompt injections more effectively than regex or classifiers.","license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2026-04-20T13:27:05Z","title":"Beyond Pattern Matching: Seven Cross-Domain Techniques for Prompt Injection Detection"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2604.18248","kind":"arxiv","version":2},"verdict":{"created_at":"2026-05-10T04:38:55.130526Z","id":"f56b2ab3-3ad2-4deb-9ec9-c5db6bd17555","model_set":{"reader":"grok-4.3"},"one_line_summary":"Seven cross-domain techniques for prompt injection detection are proposed; three implemented versions raise F1 scores on multiple benchmarks while releasing all code and data.","pipeline_version":"pith-pipeline@v0.9.0","pith_extraction_headline":"Seven techniques borrowed from bioinformatics, linguistics, and other fields detect prompt injections more effectively than regex or classifiers.","strongest_claim":"The local-alignment detector lifts F1 on deepset from 0.033 to 0.378 with zero additional false positives. The stylometric detector adds 11.1 percentage points of F1 on an indirect-injection benchmark.","weakest_assumption":"That mechanisms proven in their original domains (sequence alignment, fatigue analysis, etc.) will transfer to LLM prompt injection without being bypassed by adaptive adversaries or introducing new failure modes not captured in the six evaluation datasets."}},"verdict_id":"f56b2ab3-3ad2-4deb-9ec9-c5db6bd17555"}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:65b1776e31b257ac1144cdba30520e8fe2d30e1d84185bcf68bfd11851758daf","target":"record","created_at":"2026-05-20T00:05:44Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"65072f82d2b9aac8b5d15547c412646aa1df0076e9143dc99c9a04008da479fd","cross_cats_sorted":["cs.CL"],"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2026-04-20T13:27:05Z","title_canon_sha256":"22ee573876f9c2fc734740f96a98698e5de844d0d13b190286e8cbf7950ed3d5"},"schema_version":"1.0","source":{"id":"2604.18248","kind":"arxiv","version":2}},"canonical_sha256":"41595562951c824a484ef1adac569648fc63092c2099d1355cd59c24408cc4f1","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"41595562951c824a484ef1adac569648fc63092c2099d1355cd59c24408cc4f1","first_computed_at":"2026-05-20T00:05:44.845693Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-05-20T00:05:44.845693Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"gkPDp86XAFYR39IJadXOiCMCIuFGChkmaMFM39w6JiTQLMY0CoJxLTCtMZj8MQ0fcpNe3xwDYedv284g6ygoCw==","signature_status":"signed_v1","signed_at":"2026-05-20T00:05:44.846309Z","signed_message":"canonical_sha256_bytes"},"source_id":"2604.18248","source_kind":"arxiv","source_version":2}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:65b1776e31b257ac1144cdba30520e8fe2d30e1d84185bcf68bfd11851758daf","sha256:3b15afac842a01c0ef55887a7b8bcc18f5991f7b5293dd3cb0d244065226aa9f"],"state_sha256":"0ff8a5697f81659d82432546f037b68dcf06c2d4ad76506ea5a339cc73d7c75c"}