{"id":"https://openalex.org/W7117888937","doi":"https://doi.org/10.1109/milcom64451.2025.11310042","title":"Model-Agnostic Unsupervised Detection of Prompt Injection with Multiscale Perplexity Signatures","display_name":"Model-Agnostic Unsupervised Detection of Prompt Injection with Multiscale Perplexity Signatures","publication_year":2025,"publication_date":"2025-10-06","ids":{"openalex":"https://openalex.org/W7117888937","doi":"https://doi.org/10.1109/milcom64451.2025.11310042"},"language":null,"primary_location":{"id":"doi:10.1109/milcom64451.2025.11310042","is_oa":false,"landing_page_url":"https://doi.org/10.1109/milcom64451.2025.11310042","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"MILCOM 2025 - 2025 IEEE Military Communications Conference (MILCOM)","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5071723292","display_name":"Jielun Zhang","orcid":"https://orcid.org/0000-0002-2113-2104"},"institutions":[{"id":"https://openalex.org/I24571045","display_name":"University of North Dakota","ror":"https://ror.org/04a5szx83","country_code":"US","type":"education","lineage":["https://openalex.org/I24571045"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Jielun Zhang","raw_affiliation_strings":["University of North Dakota,School of Electrical Engineering and Computer Science,Grand Forks,ND,USA,58202"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"University of North Dakota,School of Electrical Engineering and Computer Science,Grand Forks,ND,USA,58202","institution_ids":["https://openalex.org/I24571045"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5029012510","display_name":"Fuhao Li","orcid":"https://orcid.org/0000-0001-8076-2221"},"institutions":[{"id":"https://openalex.org/I123200800","display_name":"La Sierra University","ror":"https://ror.org/05g1rjn35","country_code":"US","type":"education","lineage":["https://openalex.org/I123200800"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Fuhao Li","raw_affiliation_strings":["La Sierra University,Computer Science Department,Riverside,CA,USA,92505"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"La Sierra University,Computer Science Department,Riverside,CA,USA,92505","institution_ids":["https://openalex.org/I123200800"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":2,"corresponding_author_ids":[],"corresponding_institution_ids":[],"apc_list":null,"apc_paid":null,"fwci":0.0,"has_fulltext":false,"cited_by_count":0,"citation_normalized_percentile":{"value":0.78675852,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":null,"biblio":{"volume":null,"issue":null,"first_page":"1","last_page":"6"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.6424000263214111,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.6424000263214111,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11424","display_name":"Security and Verification in Computing","score":0.07980000227689743,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":0.07400000095367432,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/perplexity","display_name":"Perplexity","score":0.9879999756813049},{"id":"https://openalex.org/keywords/reliability","display_name":"Reliability (semiconductor)","score":0.5870000123977661},{"id":"https://openalex.org/keywords/sliding-window-protocol","display_name":"Sliding window protocol","score":0.5023000240325928},{"id":"https://openalex.org/keywords/statistical-model","display_name":"Statistical model","score":0.41530001163482666},{"id":"https://openalex.org/keywords/window","display_name":"Window (computing)","score":0.4056999981403351},{"id":"https://openalex.org/keywords/language-model","display_name":"Language model","score":0.3273000121116638}],"concepts":[{"id":"https://openalex.org/C100279451","wikidata":"https://www.wikidata.org/wiki/Q372193","display_name":"Perplexity","level":3,"score":0.9879999756813049},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.7501999735832214},{"id":"https://openalex.org/C43214815","wikidata":"https://www.wikidata.org/wiki/Q7310987","display_name":"Reliability (semiconductor)","level":3,"score":0.5870000123977661},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.5598000288009644},{"id":"https://openalex.org/C102392041","wikidata":"https://www.wikidata.org/wiki/Q592860","display_name":"Sliding window protocol","level":3,"score":0.5023000240325928},{"id":"https://openalex.org/C114289077","wikidata":"https://www.wikidata.org/wiki/Q3284399","display_name":"Statistical model","level":2,"score":0.41530001163482666},{"id":"https://openalex.org/C2778751112","wikidata":"https://www.wikidata.org/wiki/Q835016","display_name":"Window (computing)","level":2,"score":0.4056999981403351},{"id":"https://openalex.org/C119857082","wikidata":"https://www.wikidata.org/wiki/Q2539","display_name":"Machine learning","level":1,"score":0.34200000762939453},{"id":"https://openalex.org/C137293760","wikidata":"https://www.wikidata.org/wiki/Q3621696","display_name":"Language model","level":2,"score":0.3273000121116638},{"id":"https://openalex.org/C204321447","wikidata":"https://www.wikidata.org/wiki/Q30642","display_name":"Natural language processing","level":1,"score":0.31529998779296875},{"id":"https://openalex.org/C168167062","wikidata":"https://www.wikidata.org/wiki/Q1117970","display_name":"Component (thermodynamics)","level":2,"score":0.29809999465942383},{"id":"https://openalex.org/C195324797","wikidata":"https://www.wikidata.org/wiki/Q33742","display_name":"Natural language","level":2,"score":0.29739999771118164},{"id":"https://openalex.org/C153180895","wikidata":"https://www.wikidata.org/wiki/Q7148389","display_name":"Pattern recognition (psychology)","level":2,"score":0.2939999997615814},{"id":"https://openalex.org/C2779662365","wikidata":"https://www.wikidata.org/wiki/Q5416694","display_name":"Event (particle physics)","level":2,"score":0.28999999165534973},{"id":"https://openalex.org/C124101348","wikidata":"https://www.wikidata.org/wiki/Q172491","display_name":"Data mining","level":1,"score":0.2648000121116638},{"id":"https://openalex.org/C177769412","wikidata":"https://www.wikidata.org/wiki/Q278090","display_name":"Prior probability","level":3,"score":0.26100000739097595}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1109/milcom64451.2025.11310042","is_oa":false,"landing_page_url":"https://doi.org/10.1109/milcom64451.2025.11310042","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"MILCOM 2025 - 2025 IEEE Military Communications Conference (MILCOM)","raw_type":"proceedings-article"}],"best_oa_location":null,"sustainable_development_goals":[],"awards":[],"funders":[],"has_content":{"grobid_xml":false,"pdf":false},"content_urls":null,"referenced_works_count":5,"referenced_works":["https://openalex.org/W2979826702","https://openalex.org/W4390638022","https://openalex.org/W4403507961","https://openalex.org/W4403792158","https://openalex.org/W4410609100"],"related_works":[],"abstract_inverted_index":{"Prompt":[0],"injection":[1,51],"represents":[2],"a":[3,45],"critical":[4],"and":[5,12,79,116],"increasingly":[6],"prevalent":[7],"threat":[8],"to":[9,23,34,76,90,104],"the":[10,117,121,127],"safety":[11],"reliability":[13],"of":[14,67],"large":[15],"language":[16],"models":[17],"(LLMs).":[18],"These":[19,85],"attacks":[20],"enable":[21],"adversaries":[22],"override":[24],"intended":[25],"instructions":[26],"using":[27],"only":[28],"natural":[29],"language,":[30],"often":[31],"without":[32],"access":[33],"model":[35,68],"parameters":[36],"or":[37],"system":[38],"internals.":[39],"In":[40],"this":[41],"work,":[42],"we":[43,59],"propose":[44],"model-agnostic,":[46],"unsupervised":[47],"framework":[48],"for":[49],"prompt":[50],"detection":[52,141],"based":[53],"on":[54,101,112],"token-level":[55],"uncertainty":[56],"dynamics.":[57],"Specifically,":[58],"introduce":[60],"multi-scale":[61],"perplexity":[62,69,123],"signatures,":[63],"i.e.,":[64],"structured":[65],"representations":[66],"computed":[70],"across":[71,139],"multiple":[72,140],"sliding":[73],"window":[74],"sizes,":[75],"capture":[77],"local":[78],"global":[80],"fluctuations":[81],"in":[82,132],"predictive":[83],"confidence.":[84],"signatures":[86,124],"serve":[87],"as":[88,95],"input":[89],"lightweight":[91],"statistical":[92],"classifiers,":[93],"such":[94],"OC-SVMs,":[96],"which":[97],"are":[98,110,130],"trained":[99],"exclusively":[100],"clean":[102,137],"prompts":[103,135],"detect":[105],"anomalous":[106],"inputs.":[107],"Extensive":[108],"experiments":[109],"conducted":[111],"an":[113],"open":[114],"dataset,":[115],"results":[118],"demonstrate":[119],"that":[120],"multiscale":[122],"captured":[125],"by":[126],"proposed":[128],"approach":[129],"effective":[131],"distinguishing":[133],"injected":[134],"from":[136],"ones":[138],"models.":[142]},"counts_by_year":[],"updated_date":"2026-06-11T09:08:48.828518","created_date":"2026-01-01T00:00:00"}
