{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,1,2]],"date-time":"2026-01-02T05:57:50Z","timestamp":1767333470184,"version":"3.48.0"},"reference-count":18,"publisher":"IEEE","license":[{"start":{"date-parts":[[2025,10,6]],"date-time":"2025-10-06T00:00:00Z","timestamp":1759708800000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2025,10,6]],"date-time":"2025-10-06T00:00:00Z","timestamp":1759708800000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2025,10,6]]},"DOI":"10.1109\/milcom64451.2025.11310042","type":"proceedings-article","created":{"date-parts":[[2026,1,1]],"date-time":"2026-01-01T18:35:33Z","timestamp":1767292533000},"page":"1-6","source":"Crossref","is-referenced-by-count":0,"title":["Model-Agnostic Unsupervised Detection of Prompt Injection with Multiscale Perplexity Signatures"],"prefix":"10.1109","author":[{"given":"Jielun","family":"Zhang","sequence":"first","affiliation":[{"name":"University of North Dakota,School of Electrical Engineering and Computer Science,Grand Forks,ND,USA,58202"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Fuhao","family":"Li","sequence":"additional","affiliation":[{"name":"La Sierra University,Computer Science Department,Riverside,CA,USA,92505"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"263","reference":[{"article-title":"Toward generalizable evaluation in the llm era: A survey beyond benchmarks","year":"2025","author":"Cao","key":"ref1"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.1145\/3664647.3680616"},{"volume":"1","article-title":"Prompt injection attack against llm-integrated applications (2023)","author":"Liu","key":"ref3"},{"key":"ref4","first-page":"1831","article-title":"Formalizing and benchmarking prompt injection attacks and defenses","volume-title":"33rd USENIX Security Symposium (USENIX Security 24)","author":"Liu"},{"article-title":"Multilingual jailbreak challenges in large language models","year":"2023","author":"Deng","key":"ref5"},{"article-title":"Baseline defenses for adversarial attacks against aligned language models","year":"2023","author":"Jain","key":"ref6"},{"article-title":"Intention analysis makes llms a good jailbreak defender","year":"2024","author":"Zhang","key":"ref7"},{"article-title":"Jailbreaking leading safety-aligned llms with simple adaptive attacks","year":"2024","author":"Andriushchenko","key":"ref8"},{"article-title":"Detecting language model attacks with perplexity","year":"2023","author":"Alon","key":"ref9"},{"article-title":"Large language models are human-level prompt engineers","volume-title":"The Eleventh International Conference on Learning Representations","author":"Zhou","key":"ref10"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1007\/978-981-99-7962-2_30"},{"article-title":"Ignore previous prompt: Attack techniques for language models","year":"2022","author":"Perez","key":"ref12"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.1109\/SaTML64287.2025.00010"},{"article-title":"Jailbreaking chatgpt via prompt engineering: An empirical study","year":"2023","author":"Liu","key":"ref14"},{"article-title":"Palisade\u2013prompt injection detection framework","year":"2024","author":"Kokkula","key":"ref15"},{"key":"ref16","doi-asserted-by":"crossref","DOI":"10.31219\/osf.io\/z8jk3","article-title":"Jailbreaking and mitigation of vulnerabilities in large language models","author":"Peng","year":"2024"},{"key":"ref17","article-title":"Prompt Injections Dataset"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2020.emnlp-demos.6"}],"event":{"name":"MILCOM 2025 - 2025 IEEE Military Communications Conference (MILCOM)","start":{"date-parts":[[2025,10,6]]},"location":"Los Angeles, CA, USA","end":{"date-parts":[[2025,10,10]]}},"container-title":["MILCOM 2025 - 2025 IEEE Military Communications Conference (MILCOM)"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx8\/11309822\/11309347\/11310042.pdf?arnumber=11310042","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,1,2]],"date-time":"2026-01-02T05:55:01Z","timestamp":1767333301000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/11310042\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,10,6]]},"references-count":18,"URL":"https:\/\/doi.org\/10.1109\/milcom64451.2025.11310042","relation":{},"subject":[],"published":{"date-parts":[[2025,10,6]]}}}