SCALES: Dual Information-Theoretic Approaches to Mitigating and Quantifying Prompt Injections in RAG Pipelines
| dc.contributor.advisor | Thamilarasu, Geethapriya | |
| dc.contributor.author | Ankita Maria John, - | |
| dc.date.accessioned | 2026-09-16T18:24:50Z | |
| dc.date.issued | 2026-09-16 | |
| dc.date.submitted | 2026 | |
| dc.description | Thesis (Master's)--University of Washington, 2026 | |
| dc.description.abstract | Large language models deployed within Retrieval-Augmented Generation (RAG) systems are vulnerable to indirect prompt injection, where adversarial instructions embedded in retrieved documents cause the model to override its intended behaviour, exfiltrate confidential context, or execute unauthorised actions. This thesis makes two complementary contributions to securing RAG pipelines. The first is SCALES (Semantic Cascade Architecture for Leakage and Exploitation Security), a modality-aware three-layer defense cascade combining a DeBERTa-based pre-retrieval classifier, a KL-divergence semantic boundary chunker, and an IT-MOC LoRA adapter regularised with Jensen-Shannon Divergence. Evaluated on a 425-sample benchmark spanning explicit text injections, LLM-generated semantic attacks, gradient optimised adaptive attacks, and cross-modal decomposition attacks, SCALES achieves a judge-verified Attack Success Rate of 6.5\% and a Benign Pass Rate of 95.33\%. The second contribution is an information-theoretic evaluation framework that quantifies data leakage severity beyond binary attack success, combining four complementary metrics, lexical, semantic, algorithmic, and distributional similarity, into a Combined Leakage Index validated against LLM-judge harm scores. Per-source decomposition reveals that SCALES suppresses leakage by 99\% on adaptive attacks focused on data leakage demonstrating a level of diagnostic granularity unavailable to single-metric evaluation. | |
| dc.embargo.lift | 2028-09-05T18:24:50Z | |
| dc.embargo.terms | Restrict to UW for 2 years -- then make Open Access | |
| dc.format.mimetype | application/pdf | |
| dc.identifier.other | AnkitaMariaJohn_washington_0250O_30147.pdf | |
| dc.identifier.uri | https://hdl.handle.net/1773/57746 | |
| dc.language.iso | en_US | |
| dc.rights | none | |
| dc.subject | Information Theoretics | |
| dc.subject | RAG | |
| dc.subject | Security | |
| dc.subject | Computer science | |
| dc.subject | Information technology | |
| dc.subject.other | Computer science and engineering | |
| dc.title | SCALES: Dual Information-Theoretic Approaches to Mitigating and Quantifying Prompt Injections in RAG Pipelines | |
| dc.type | Thesis |
Files
Original bundle
1 - 1 of 1
Loading...
- Name:
- AnkitaMariaJohn_washington_0250O_30147.pdf
- Size:
- 1.43 MB
- Format:
- Adobe Portable Document Format
