cs.CRJul 3, 2025

Meta-SecAlign: Training LLMs against Prompt Injection for Robust Agents

Authors: Sizhe Chen, Arman Zharmagambetov, David Wagner, Chuan Guo

Organizations: FAIR at Meta · UC Berkeley

Abstract

Prompt injection attacks, where untrusted data contains an injected prompt to manipulate the system, have been listed as the top security threat to AI agents. By fine-tuning on simulated prompt injections, SecAlign, a leading open defense, reports LLMs with good test-time robustness and negligible benign utility drop. By scaling up training and evaluations, however, we find that SecAlign actually suffers from significant utility degradation, especially in agentic tasks where the threat of prompt injection is prominent. Motivated by this, we propose Meta-SecAlign for utility-preserving defense by (1) randomized injection position during training to avoid shortcut learning and (2) self-generated responses as high-quality in-distribution training labels. Across general knowledge, instruction following, and agentic workflows (on tool-calling and web-navigation), Meta-SecAlign maintains almost all the undefended LLM's utility while achieving better overall security than SecAlign against various static and GCG adaptive attacks. Experiments use Llama-3.1-8B, Llama-3.3-70B, Llama-4-Scout, Qwen3-4B, and Qwen3.6-27B on 6 prompt injection benchmarks including AgentDojo, InjecAgent, WASP, and SEP. Below are links for the code (https://github.com/facebookresearch/Meta_SecAlign), Meta-SecAlign-70B (https://huggingface.co/facebook/Meta-SecAlign-70B), and Meta-SecAlign-8B (https://huggingface.co/facebook/Meta-SecAlign-8B) models.

Figures & tables

Appendix figures & tables4 assets

Supplementary material from the paper’s appendix.

Appendix

Explore similar work

CardsList
  1. AgentAntibody: An Adaptive Immune System for Defending LLM Agents against Prompt Injection

    Aug 4, 2026Shihao Weng, Yang Feng, Xiaofei Xie +1Multi-Llm AgentsPrompt Engineering

  2. Assessing Automated Prompt Injection Attacks in Agentic Environments

    Jun 9, 2026David Hofer, Edoardo Debenedetti, Florian TramèrIndirect Prompt InjectionLarge Language Model Agents

  3. IterInject: Indirect Prompt Injection Against LLM Agents via Feedback-Guided Iterative Optimization

    May 23, 2026Zixuan Chen, Jiaxiang Chen, Li Luo +4Indirect Prompt InjectionLarge Language Model Agents