[ICML'25] MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents
☆39Jul 31, 2025Updated last year
Alternatives and similar repositories for MELON
Users that are interested in MELON are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- [NeurIPS 2025] The official implementation of the paper "DRIFT: Dynamic Rule-Based Defense with Injection Isolation for Securing LLM Agen…☆61Jul 16, 2026Updated 2 months ago
- ☆24Dec 18, 2025Updated 9 months ago
- Agent Security Bench (ASB)☆305Apr 16, 2026Updated 5 months ago
- [EMNLP 2025 Oral] IPIGuard: A Novel Tool Dependency Graph-Based Defense Against Indirect Prompt Injection in LLM Agents☆25Sep 16, 2025Updated last year
- ☆171Jul 2, 2024Updated 2 years ago
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- A Dynamic Environment to Evaluate Attacks and Defenses for LLM Agents.☆870Jun 2, 2026Updated 3 months ago
- PISmith: Reinforcement Learning-based Red Teaming for Prompt Injection Defenses(COLM 2026)☆31Aug 27, 2026Updated last month
- Memory Injection Attacks on LLM Agents via Query-Only Interaction☆37Aug 11, 2026Updated last month
- [ICLR 2026] Official implementation of "ChatInject: Abusing Chat Templates for Prompt Injection in LLM Agents"☆24Mar 23, 2026Updated 6 months ago
- Flow Integrity Deterministic Enforcement System. Mechanisms for securing AI agents with information-flow control.☆117May 30, 2025Updated last year
- [ACL 2025] The official code for "AGrail: A Lifelong Agent Guardrail with Effective and Adaptive Safety Detection".☆45Aug 12, 2026Updated last month
- ☆17Jul 2, 2026Updated 2 months ago
- AgentSentinel: An End-to-End and Real-Time Security Defense Framework for Computer-Use Agents☆39Aug 31, 2025Updated last year
- MCPSecBench: A Systematic Security Benchmark and Playground for Testing Model Context Protocols☆36Mar 4, 2026Updated 6 months ago
- Virtual machines for every use case on DigitalOcean • AdGet dependable uptime with 99.99% SLA, simple security tools, and predictable monthly pricing with DigitalOcean's virtual machines, called Droplets.
- The official implementation of the paper "AgentDyn: Are Your Agent Security Defenses Deployable in Real-World Dynamic Environments?"☆82May 19, 2026Updated 4 months ago
- The implementation for paper "UniGuardian: A Unified Defense for Detecting Prompt Injection, Backdoor Attacks and Adversarial Attacks in …☆17Jul 3, 2025Updated last year
- PFI: Prompt Flow Integrity to Prevent Privilege Escalation in LLM Agents☆32Mar 26, 2025Updated last year
- Scripts for drawing figures in your paper☆11Jan 8, 2025Updated last year
- Official implementation of the WASP web agent security benchmark☆97Apr 13, 2026Updated 5 months ago
- Official Implementation of "ToolSafe: Enhancing Tool Invocation Safety of LLM-based Agents via Proactive Step-level Guardrail and Feedbac…☆80Mar 25, 2026Updated 6 months ago
- ☆18Mar 9, 2025Updated last year
- ☆21Feb 6, 2026Updated 7 months ago
- Code for the paper "Defeating Prompt Injections by Design"☆394Jun 20, 2025Updated last year
- GPUs on demand by Runpod - Special Offer Available • AdRun AI, ML, and HPC workloads on powerful cloud GPUs—without limits or wasted spend. Deploy GPUs in under a minute and pay by the second.
- ☆41Mar 12, 2025Updated last year
- [CCS 2024] Optimization-based Prompt Injection Attack to LLM-as-a-Judge☆41Sep 17, 2025Updated last year
- [ICLR 2025] Dissecting adversarial robustness of multimodal language model agents☆144Feb 19, 2025Updated last year
- Source code for the ACL'2025 paper titled "Unveiling privacy risks in llm agent memory"☆38Dec 2, 2025Updated 9 months ago
- This repository provides a benchmark for prompt injection attacks and defenses in LLMs☆503Updated this week
- Repository for the Paper: Leave My Images Alone: Preventing Multi-Modal Large Language Models from Analyzing Images via Visual Prompt Inj…☆21Apr 17, 2026Updated 5 months ago
- ☆22Dec 14, 2023Updated 2 years ago
- Code for our ICLR 2023 paper Making Substitute Models More Bayesian Can Enhance Transferability of Adversarial Examples.☆18May 31, 2023Updated 3 years ago
- Code for our NAACL2025 accepted paper: Attention Tracker: Detecting Prompt Injection Attacks in LLMs☆32Sep 19, 2025Updated last year
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- A Security Benchmark for Claude Code Agent Skills☆78Aug 3, 2026Updated last month
- [NeurIPS'24] RedCode: Risky Code Execution and Generation Benchmark for Code Agents☆91Aug 19, 2026Updated last month
- ☆25Dec 15, 2025Updated 9 months ago
- ☆67Jun 24, 2026Updated 3 months ago
- ☆36Feb 27, 2025Updated last year
- Mobile GUI Agents under Real-world Threats: Are We There Yet?☆18Aug 4, 2026Updated last month
- Codes for our paper "AgentMonitor: A Plug-and-Play Framework for Predictive and Secure Multi-Agent Systems"☆14Dec 13, 2024Updated last year