Fetching from the wire…
Public story · 2026-08-25 · high
SecOPD trains on token-level feedback instead of whole-sequence signal, cutting adaptive attack success from 94% to 9%.
Why now: The paper posted August 25.
SecOPD, a new prompt-injection defense, drops adaptive attack success to 9.0% against PISmith injections on Qwen3.6-27B, per the SecOPD paper.
Meta-SecAlign, the previous best defense, let 94.0% of those same PISmith adaptive injections through on Qwen3.6-27B. Adaptive attacks are built to beat a defense once its exact behavior is already public, and every earlier defense before SecOPD broke against them. That matters for anyone running an agent that calls tools or reads content it doesn't control.
The gap comes from the training signal, the paper reports. SecOPD fine-tunes on token-level feedback during on-policy distillation, where Meta-SecAlign and other prior defenses trained on sequence-level feedback instead.
SecOPD also holds up outside the injection setting it was tuned on, cutting attack success to 4.7% on agentic tool calling. The model never saw that domain during training. That result points at the training signal as the fix for adaptive attacks, not broader domain coverage.
Each link below shares sources, entities, or timing with this story.
Meta criticizes OpenClaw / Shared entities / Same source domain / Earlier coverage
Linked by a graph relationship (Meta criticizes OpenClaw); both cover Meta, Qwen3; reported by the same outlet (arxiv.org).
Meta criticizes OpenClaw / Shared entities / Earlier coverage
Linked by a graph relationship (Meta criticizes OpenClaw); both cover Meta, Qwen3; earlier Meta coverage from 2026-08-10.
Meta uses Gemini / Shared entities / Earlier coverage
Linked by a graph relationship (Meta uses Gemini); both cover Meta, Qwen3; earlier Meta coverage from 2026-04-02.
Meta released Llama / Shared entity: Token / Same source domain / Earlier coverage
Linked by a graph relationship (Meta released Llama); both cover Token; reported by the same outlet (arxiv.org).
Meta released Llama / Shared entity: Qwen3 / Same source domain / Earlier coverage
Linked by a graph relationship (Meta released Llama); both cover Qwen3; reported by the same outlet (arxiv.org).
Meta partners with Google / Shared entity: Meta / Shared topic / Earlier coverage
Linked by a graph relationship (Meta partners with Google); both cover Meta; overlapping topics (against, agentic).
Meta released Llama / Same source domain / Shared topic
Linked by a graph relationship (Meta released Llama); reported by the same outlet (arxiv.org); overlapping topics (against, attack, success).
Meta uses Gemini / Shared entity: Meta / Earlier coverage / Tension
Linked by a graph relationship (Meta uses Gemini); both cover Meta; earlier Meta coverage from 2026-08-09.