{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2024:U5DIXMVVURYYAFNKFYSGW4VSEM","short_pith_number":"pith:U5DIXMVV","schema_version":"1.0","canonical_sha256":"a7468bb2b5a4718015aa2e246b72b22303e4a18b6591de7b51eab94db4cd0f11","source":{"kind":"arxiv","id":"2410.21492","version":2},"attestation_state":"computed","paper":{"title":"FATH: Authentication-based Test-time Defense against Indirect Prompt Injection Attacks","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.CL"],"primary_cat":"cs.CR","authors_text":"Chaowei Xiao, Edward Suh, Fangzhou Wu, Jinsheng Pan, Jiongxiao Wang, Muhao Chen, Wendi Li, Z. Morley Mao","submitted_at":"2024-10-28T20:02:47Z","abstract_excerpt":"Large language models (LLMs) have been widely deployed as the backbone with additional tools and text information for real-world applications. However, integrating external information into LLM-integrated applications raises significant security concerns. Among these, prompt injection attacks are particularly threatening, where malicious instructions injected in the external text information can exploit LLMs to generate answers as the attackers desire. While both training-time and test-time defense methods have been developed to mitigate such attacks, the unaffordable training costs associated"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2410.21492","kind":"arxiv","version":2},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2024-10-28T20:02:47Z","cross_cats_sorted":["cs.CL"],"title_canon_sha256":"4882e7157cd286b8876265ce223226b1411c885116e22c80a7dc5eb83e5c014e","abstract_canon_sha256":"7c7bd22bbfdb19507e98757d57ae688f68124bf3a715c56938231799e2b239a0"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T09:40:20.525660Z","signature_b64":"HtlRQ9fjDr19qmA39+zWluDnEZ1CgMIoM/yI4PPiZzI9ad/dc09Ct4WP6Dw1fzKVxs1q1DJXqpTPq94tMabaCA==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"a7468bb2b5a4718015aa2e246b72b22303e4a18b6591de7b51eab94db4cd0f11","last_reissued_at":"2026-07-05T09:40:20.525226Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T09:40:20.525226Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"FATH: Authentication-based Test-time Defense against Indirect Prompt Injection Attacks","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.CL"],"primary_cat":"cs.CR","authors_text":"Chaowei Xiao, Edward Suh, Fangzhou Wu, Jinsheng Pan, Jiongxiao Wang, Muhao Chen, Wendi Li, Z. Morley Mao","submitted_at":"2024-10-28T20:02:47Z","abstract_excerpt":"Large language models (LLMs) have been widely deployed as the backbone with additional tools and text information for real-world applications. However, integrating external information into LLM-integrated applications raises significant security concerns. Among these, prompt injection attacks are particularly threatening, where malicious instructions injected in the external text information can exploit LLMs to generate answers as the attackers desire. While both training-time and test-time defense methods have been developed to mitigate such attacks, the unaffordable training costs associated"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2410.21492","kind":"arxiv","version":2},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2410.21492/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2410.21492","created_at":"2026-07-05T09:40:20.525274+00:00"},{"alias_kind":"arxiv_version","alias_value":"2410.21492v2","created_at":"2026-07-05T09:40:20.525274+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2410.21492","created_at":"2026-07-05T09:40:20.525274+00:00"},{"alias_kind":"pith_short_12","alias_value":"U5DIXMVVURYY","created_at":"2026-07-05T09:40:20.525274+00:00"},{"alias_kind":"pith_short_16","alias_value":"U5DIXMVVURYYAFNK","created_at":"2026-07-05T09:40:20.525274+00:00"},{"alias_kind":"pith_short_8","alias_value":"U5DIXMVV","created_at":"2026-07-05T09:40:20.525274+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":6,"internal_anchor_count":0,"sample":[{"citing_arxiv_id":"2606.03136","citing_title":"PsychoPass: Geometric Profiling of Multi-Turn Adversarial LLM Conversations","ref_index":24,"is_internal_anchor":false},{"citing_arxiv_id":"2605.24309","citing_title":"Reframing LLM Agent Security as an Agent-Human Interaction Problem","ref_index":54,"is_internal_anchor":false},{"citing_arxiv_id":"2504.20472","citing_title":"Robustness via Referencing: Defending against Prompt Injection Attacks by Referencing the Executed Instruction","ref_index":42,"is_internal_anchor":false},{"citing_arxiv_id":"2605.09033","citing_title":"ShadowMerge: A Novel Poisoning Attack on Graph-Based Agent Memory via Relation-Channel Conflicts","ref_index":49,"is_internal_anchor":false},{"citing_arxiv_id":"2605.09033","citing_title":"ShadowMerge: A Novel Poisoning Attack on Graph-Based Agent Memory via Relation-Channel Conflicts","ref_index":49,"is_internal_anchor":false},{"citing_arxiv_id":"2605.09033","citing_title":"ShadowMerge: A Novel Poisoning Attack on Graph-Based Agent Memory via Relation-Channel Conflicts","ref_index":48,"is_internal_anchor":false}]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/U5DIXMVVURYYAFNKFYSGW4VSEM","json":"https://pith.science/pith/U5DIXMVVURYYAFNKFYSGW4VSEM.json","graph_json":"https://pith.science/api/pith-number/U5DIXMVVURYYAFNKFYSGW4VSEM/graph.json","events_json":"https://pith.science/api/pith-number/U5DIXMVVURYYAFNKFYSGW4VSEM/events.json","paper":"https://pith.science/paper/U5DIXMVV"},"agent_actions":{"view_html":"https://pith.science/pith/U5DIXMVVURYYAFNKFYSGW4VSEM","download_json":"https://pith.science/pith/U5DIXMVVURYYAFNKFYSGW4VSEM.json","view_paper":"https://pith.science/paper/U5DIXMVV","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2410.21492&json=true","fetch_graph":"https://pith.science/api/pith-number/U5DIXMVVURYYAFNKFYSGW4VSEM/graph.json","fetch_events":"https://pith.science/api/pith-number/U5DIXMVVURYYAFNKFYSGW4VSEM/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/U5DIXMVVURYYAFNKFYSGW4VSEM/action/timestamp_anchor","attest_storage":"https://pith.science/pith/U5DIXMVVURYYAFNKFYSGW4VSEM/action/storage_attestation","attest_author":"https://pith.science/pith/U5DIXMVVURYYAFNKFYSGW4VSEM/action/author_attestation","sign_citation":"https://pith.science/pith/U5DIXMVVURYYAFNKFYSGW4VSEM/action/citation_signature","submit_replication":"https://pith.science/pith/U5DIXMVVURYYAFNKFYSGW4VSEM/action/replication_record"}},"created_at":"2026-07-05T09:40:20.525274+00:00","updated_at":"2026-07-05T09:40:20.525274+00:00"}