Research
Prompt Injection Defenses Look Good Only Because Benchmarks Are Short: LongPIBench Breaks Them at Tens of Thousands of Tokens
LongPIBench (arXiv 2608.28411, 2026-08-28, cs.AI/cs.CR) argues existing prompt-injection benchmarks concentrate on short contexts and therefore substantially overestimate current defenses. It covers four realistic scenarios (paper peer review, resume screening, code review, email summary), each with a synthetic and a real-world dataset at context lengths from thousands to tens of thousands of tokens. Evaluation results show even simple heuristic injection attacks reach high success rates and frequently bypass state-of-the-art defenses in the long-context setting, which is exactly the regime production agents run in.
↳ Follow the thread