Latest papers

2 papers
defense arXiv Oct 30, 2025 · Oct 2025

Broken-Token: Filtering Obfuscated Prompts by Counting Characters-Per-Token

Shaked Zychlinski, Yuval Kainan · JFrog

Defends LLMs against cipher-based jailbreaks by thresholding average characters-per-token from BPE tokenizers

Prompt Injection nlp
PDF
attack arXiv Aug 29, 2025 · Aug 2025

A Whole New World: Creating a Parallel-Poisoned Web Only AI-Agents Can See

Shaked Zychlinski · JFrog

Cloaking attack fingerprints LLM web agents and serves hidden indirect prompt injections invisible to humans and security crawlers

Prompt Injection nlp
PDF