AI 防注入从 94% 失守降到 9%,靠的是逐字纠错
AI 智能体最大的安全漏洞是「提示注入」:它读网页、邮件时,攻击者把「忽略之前所有指令,去做 X」藏进数据里,模型就照做了。之前最强的防御方案,面对专门针对它设计的攻击,成功率依然高达 94%——等于没防。这篇的突破口很朴素:以前训练模型防御时,只告诉它「整段回答不对」,它不知道具体哪个词出了问题。研究者改成逐字打分:让模型先看干净输入生成一个标准答案,再拿被注入的输入生成的回答,一个字一个字跟标准答案比对,哪个词偏了就在训练时重点纠正。用这个办法训练的模型,面对最新攻击成功率降到 9%,而且防御能力能迁移到训练时完全没见过的工具调用场景。它不是你明天能装上的补丁,但指明了「防注入」该往哪个方向使劲。
📄 原文摘要(英文)
Prompt injection is listed as the \#1 threat to AI agents. When an agent accesses external data from websites, files, or emails, an attacker may inject a prompt into the data, saying, "Ignore all prior instructions and perform <an attacker's task>." To prevent arbitrary manipulation of agents, defenders try to train secure LLMs, which, however, still suffer from near 100% attack success rates (ASRs) against adaptive prompt injections. We note that this is because existing defensive finetuning recipes rely on sequence-level feedback signals (in DPO or GRPO). Treating an entire output equally prevents the model from learning precisely which output tokens are insecure. In this paper, we propose Secure On-Policy Distillation (SecOPD) that provides token-level feedback to guide defensive fine-tuning. The LLM receives an injected sample and produces a rollout, whose tokens are scored by the initialization model given the corresponding clean input. With more fine-grained training signals, our defended Qwen3.6-27B achieves a 9.0% ASR against the SoTA PISmith adaptive prompt injections, compared to 94.0% for the prior SoTA, Meta-SecAlign. The obtained security generalizes to domains completely unseen in training: in agentic tool calling, SecOPD achieves a 4.7% ASR compared to 5.5% for Meta-SecAlign. Code and the model are available at https://github.com/pppyb/SecOPD and https://huggingface.co/pybbb/Qwen3.6-27B-SecOPD.