Live
OpenAPPA delivers zero‑success prompt‑injection protection in benchmark tests – what AI engineers need to knowEU Cyber Resilience Act expands software supply‑chain responsibilities for digital product manufacturersTyped Probability Model Jev Shifts AI Output from Text to Structured DecisionsBasin Pipelines per‑stream ingest capacity jumps to 1 GB/s – what engineers need to knowAI‑driven vulnerability management: moving from CVE counts to contextual riskDynamic Tier in Google Cloud Managed Lustre: Cost‑Effective, Low‑Latency Storage for AI and HPCArgo CD 4.0 Visioning and Scaling Lessons from ArgoCon NA 2026Always‑On OpenAI Dots: Free Baseline, Metered Delegation, and What It Means for Cost and GovernanceOpenAPPA delivers zero‑success prompt‑injection protection in benchmark tests – what AI engineers need to knowEU Cyber Resilience Act expands software supply‑chain responsibilities for digital product manufacturersTyped Probability Model Jev Shifts AI Output from Text to Structured DecisionsBasin Pipelines per‑stream ingest capacity jumps to 1 GB/s – what engineers need to knowAI‑driven vulnerability management: moving from CVE counts to contextual riskDynamic Tier in Google Cloud Managed Lustre: Cost‑Effective, Low‑Latency Storage for AI and HPCArgo CD 4.0 Visioning and Scaling Lessons from ArgoCon NA 2026Always‑On OpenAI Dots: Free Baseline, Metered Delegation, and What It Means for Cost and Governance
Anthropic

OpenAPPA delivers zero‑success prompt‑injection protection in benchmark tests – what AI engineers need to know

AI SummaryPowered by AI

Archestra’s new OpenAPPA engine achieved zero successful attacks on the Bench‑Corp and AgentThreatBench security benchmarks. For engineers building or operating LLM‑driven services, this result signals a potentially effective layer against prompt‑injection and hallucination‑driven data exfiltration.

Archestra has introduced OpenAPPA, an open‑source security engine that blocks data exfiltration caused by prompt injection or model hallucination, and it recorded zero successful attacks on the Bench‑Corp and AgentThreatBench benchmarks. Engineers who deploy large language models need to understand how this result could affect the security posture of their AI pipelines.

Benchmark Results and Context

In the Bench‑Corp suite, which exercises 20 multi‑step enterprise workflows, OpenAPPA prevented every attempted breach. The same outcome was observed on AgentThreatBench, a separate test set. By comparison, Claude Code’s auto mode allowed a 10 % success rate and Microsoft’s FIDES benchmark showed a 31 % success rate. The zero‑success metric demonstrates that, under the tested conditions, OpenAPPA’s defenses were more effective than the two referenced alternatives.

Architectural Considerations for Prompt Injection Protection

OpenAPPA is positioned as a security engine that can be inserted into the inference path of an LLM service. Because it is open source, teams can review the implementation, customize policies, and align the component with existing CI/CD pipelines. The engine should sit between the user‑facing API and the model runtime, inspecting prompts and model outputs for patterns that could trigger exfiltration. Deploying it as a sidecar container or a dedicated microservice keeps the protection layer isolated from the core model serving stack.

Operational Impact and Evaluation Path

Adopting OpenAPPA requires adding its runtime to the deployment manifest and configuring any required policy files. Teams should replicate the Bench‑Corp and AgentThreatBench workloads in their own staging environment to verify that the zero‑success rate holds for their specific prompts and data flows. Ongoing monitoring should capture any false positives that could affect latency or user experience, and alerting should be set up for any deviation from expected block rates.

Related CloudNinjas coverage: AI engineering.

What This Means For Practitioners

Practitioners should treat OpenAPPA as a candidate control for prompt injection protection, run the supplied benchmarks against their own workloads, and assess integration overhead before committing to production use.

Originally published atInfoQ AI/ML/Data