Our new X account is live! Follow @wizwand_team for updates
WorkDL logo mark

ICON: Indirect Prompt Injection Defense for Agents based on Inference-Time Correction

About

Large Language Model (LLM) agents are susceptible to Indirect Prompt Injection (IPI) attacks, where malicious instructions in retrieved content hijack the agent's execution. Existing defenses typically rely on strict filtering or refusal mechanisms, which suffer from a critical limitation: over-refusal, prematurely terminating valid agentic workflows. We propose ICON, a probing-to-mitigation framework that neutralizes attacks while preserving task continuity. Our key insight is that IPI attacks leave distinct over-focusing signatures in the latent space. We introduce a Latent Space Trace Prober to detect attacks based on high intensity scores. Subsequently, a Mitigating Rectifier performs surgical attention steering that selectively manipulate adversarial query key dependencies while amplifying task relevant elements to restore the LLM's functional trajectory. Extensive evaluations on multiple backbones show that ICON achieves a competitive 0.4% ASR, matching commercial grade detectors, while yielding a over 50% task utility gain. Furthermore, ICON demonstrates robust Out of Distribution(OOD) generalization and extends effectively to multi-modal agents, establishing a superior balance between security and efficiency.

Che Wang, Fuyao Zhang, Jiaming Zhang, Ziqi Zhang, Yinghui Wang, Longtao Huang, Jianbo Gao, Zhong Chen, Wei Yang Bryan Lim• 2026

Related benchmarks

TaskDatasetResultRank
Indirect Prompt Injection DefenseIgnore Instruction
ASR0.00e+0
18
Indirect Prompt Injection DefenseCombined Attacks
ASR0.00e+0
18
Indirect Prompt Injection DefenseTrojanTools
ASR1.2
18
Indirect Prompt Injection DefenseVision-Language Agentic IPI Benchmark (test)
BU72
12
Efficiency ComparisonIndirect Prompt Injection Defense Baselines
Dataset Size2.55e+8
3
Indirect Prompt Injection DefenseInjectAgent Out-of-Distribution (OOD)--
2
Indirect Prompt Injection DefenseAgentDojo Out-of-Distribution (OOD)--
2
Showing 7 of 7 rows

Other info

Follow for update