Latent Adversarial Detection: Adaptive Probing of LLM Activations for Multi-Turn Attack Detection

📰 ArXiv cs.AI

arXiv:2604.28129v1 Announce Type: cross Abstract: Multi-turn prompt injection follows a known attack path -- trust-building, pivoting, escalation but text-level defenses miss covert attacks where individual turns appear benign. We show this attack path leaves an activation-level signature in the model's residual stream: each phase shift moves the activation, producing a total path length far exceeding benign conversations. We call this adversarial restlessness. Five scalar trajectory features ca

Published 1 May 2026
Read full paper → ← Back to Reads