[ICML'25] MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents
☆37Jul 31, 2025Updated 11 months ago
Alternatives and similar repositories for MELON
Users that are interested in MELON are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- [NeurIPS 2025] The official implementation of the paper "DRIFT: Dynamic Rule-Based Defense with Injection Isolation for Securing LLM Agen…☆58Jul 16, 2026Updated last week
- ☆22Dec 18, 2025Updated 7 months ago
- Agent Security Bench (ASB)☆273Apr 16, 2026Updated 3 months ago
- [EMNLP 2025 Oral] IPIGuard: A Novel Tool Dependency Graph-Based Defense Against Indirect Prompt Injection in LLM Agents☆22Sep 16, 2025Updated 10 months ago
- ☆153Jul 2, 2024Updated 2 years ago
- Virtual machines for every use case on DigitalOcean • AdGet dependable uptime with 99.99% SLA, simple security tools, and predictable monthly pricing with DigitalOcean's virtual machines, called Droplets.
- A Dynamic Environment to Evaluate Attacks and Defenses for LLM Agents.☆690Jun 2, 2026Updated last month
- PISmith: Reinforcement Learning-based Red Teaming for Prompt Injection Defenses☆22Jul 17, 2026Updated last week
- Memory Injection Attacks on LLM Agents via Query-Only Interaction☆30Feb 10, 2026Updated 5 months ago
- [ICLR 2026] Official implementation of "ChatInject: Abusing Chat Templates for Prompt Injection in LLM Agents"☆17Mar 23, 2026Updated 4 months ago
- Flow Integrity Deterministic Enforcement System. Mechanisms for securing AI agents with information-flow control.☆110May 30, 2025Updated last year
- [ACL 2025] The official code for "AGrail: A Lifelong Agent Guardrail with Effective and Adaptive Safety Detection".☆42Aug 4, 2025Updated 11 months ago
- ☆11Jul 2, 2026Updated 3 weeks ago
- AgentSentinel: An End-to-End and Real-Time Security Defense Framework for Computer-Use Agents☆35Aug 31, 2025Updated 10 months ago
- MCPSecBench: A Systematic Security Benchmark and Playground for Testing Model Context Protocols☆35Mar 4, 2026Updated 4 months ago
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- The official implementation of the paper "AgentDyn: Are Your Agent Security Defenses Deployable in Real-World Dynamic Environments?"☆69May 19, 2026Updated 2 months ago
- The implementation for paper "UniGuardian: A Unified Defense for Detecting Prompt Injection, Backdoor Attacks and Adversarial Attacks in …☆17Jul 3, 2025Updated last year
- PFI: Prompt Flow Integrity to Prevent Privilege Escalation in LLM Agents☆31Mar 26, 2025Updated last year
- Progent: Securing AI Agents with Privilege Control☆44May 14, 2026Updated 2 months ago
- ☆40Mar 24, 2026Updated 4 months ago
- Official implementation of the WASP web agent security benchmark☆98Apr 13, 2026Updated 3 months ago
- Official release of code for the paper RL is a hammer and LLMs are nails A simple RL approach to stronger prompt injection attacks☆53May 6, 2026Updated 2 months ago
- Official Implementation of "ToolSafe: Enhancing Tool Invocation Safety of LLM-based Agents via Proactive Step-level Guardrail and Feedbac…☆74Mar 25, 2026Updated 4 months ago
- ☆17Mar 9, 2025Updated last year
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- ☆21Feb 6, 2026Updated 5 months ago
- Code for the paper "Defeating Prompt Injections by Design"☆359Jun 20, 2025Updated last year
- ☆15Jun 6, 2023Updated 3 years ago
- ☆39Mar 12, 2025Updated last year
- [CCS 2024] Optimization-based Prompt Injection Attack to LLM-as-a-Judge☆41Sep 17, 2025Updated 10 months ago
- [ICLR 2025] Dissecting adversarial robustness of multimodal language model agents☆140Feb 19, 2025Updated last year
- Source code for the ACL'2025 paper titled "Unveiling privacy risks in llm agent memory"☆34Dec 2, 2025Updated 7 months ago
- This repository provides a benchmark for prompt injection attacks and defenses in LLMs☆468Oct 29, 2025Updated 8 months ago
- Evaluator for LLMs☆28Jan 25, 2024Updated 2 years ago
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- Repository for the Paper: Leave My Images Alone: Preventing Multi-Modal Large Language Models from Analyzing Images via Visual Prompt Inj…☆19Apr 17, 2026Updated 3 months ago
- ☆22Dec 14, 2023Updated 2 years ago
- Code for our NAACL2025 accepted paper: Attention Tracker: Detecting Prompt Injection Attacks in LLMs☆28Sep 19, 2025Updated 10 months ago
- A Security Benchmark for Claude Code Agent Skills☆69Jul 21, 2026Updated last week
- ☆22Dec 15, 2025Updated 7 months ago
- ☆60Jun 24, 2026Updated last month
- ☆33Feb 27, 2025Updated last year