Mitigating Prompt Injection with Model-Defined Finite Automata over Agent Trajectories
An NFA language for constraining agent tool calls over long trajectories, and evaluating it as a prompt injection defense
1187 words
6 min read