started · updated
Emory University launches SIEVE to block indirect prompt injection
Researchers at Emory University introduced SIEVE, a hybrid defense framework for autonomous large‑language‑model (LLM) agents. The system builds an Intent Graph to verify tool‑call sequences and argument provenance, escalating only ambiguous actions to a Semantic Adjudication Module. In benchmark tests (AgentLure, AgentDojo) SIEVE lowered attack success rates compared with prior defenses such as DRIFT and ARGUS while keeping token overhead low.
Security analysts at Proofpoint reported a growing underground market for tools that exploit indirect prompt injection (IPI), also called IDPI. Advertisements describe services that embed malicious prompts in calendar invites, emails, PDFs and web pages to hijack LLM‑driven workflows. The firm warned that these techniques are likely to appear in real‑world attack chains in the coming months, urging organizations to prepare for such threats.
Entities
Emory University · Indirect Prompt Injection · LLM agents · Proofpoint · SIEVE