April 2026Unreviewed
Latent Adversarial Detection: Adaptive Probing of LLM Activations for Multi-Turn Attack Detection
Prashant Kulkarni
Abstract
Multi-turn prompt injection follows a known attack path -- trust-building, pivoting, escalation but text-level defenses miss covert attacks where individual turns appear benign. We show this attack path leaves an activation-level signature in the model's residual stream: each phase shift moves the activation, producing a total path length far exceeding benign conversations. We call this adversarial restlessness. Five scalar trajectory features capturing this signal lift conversation-level detect
Categories
Framework mappings
OWASP Top 10 for LLM Applications
- LLM01Prompt Injection
MITRE ATLAS
- AML.T0051LLM Prompt Injection
Suggested from the entry's categories.
Cite
@misc{kulkarni2026latent,
title = {{Latent Adversarial Detection: Adaptive Probing of LLM Activations for Multi-Turn Attack Detection}},
author = {Prashant Kulkarni},
year = {2026},
month = apr,
eprint = {2604.28129},
archivePrefix = {arXiv},
url = {https://arxiv.org/abs/2604.28129}
}