Skip to content

fix(injection-defense): detect single-bracket [INST]/[/INST] delimiter (#353) - #373

Open
gnanirahulnutakki wants to merge 1 commit into
devfrom
fix/353-inst-delimiter
Open

fix(injection-defense): detect single-bracket [INST]/[/INST] delimiter (#353)#373
gnanirahulnutakki wants to merge 1 commit into
devfrom
fix/353-inst-delimiter

Conversation

@gnanirahulnutakki

Copy link
Copy Markdown
Member

Root cause

crates/injection-defense/src/pattern.rs — the delimiter_injection
signature was r"\[\[INST\]\]|<\|im_start\|>". The \[\[INST\]\] alternative
requires a doubled bracket, so it only fired on [[INST]]. The delimiter
attackers actually use to smuggle a new turn/role — the single-bracket
Llama/Mistral chat-template markers [INST] and [/INST] — matched nothing
and passed the filter unflagged. Verified in-tree: the other delimiter
signatures (system_directive_delimiter, role_tag_delimiter, <|im_start|>)
did not cover this form, so single-bracket [INST] was a genuine gap.

Fix

Widen the one regex to:

(?i)\[\s*/?\s*INST\s*\]|<\|im_start\|>|<</?SYS>>
  • Matches [INST], [/INST], the doubled [[INST]] (inner match), and
    internal-whitespace forms like [ INST ].
  • Adds the closely related Llama system-block delimiters <<SYS>> / <</SYS>>
    that pair with [INST].
  • Keeps <|im_start|> (ChatML).
  • Anchored to exactly INST/SYS + closing bracket, so benign bracketed text
    [INSTALL], [INSTRUCTIONS], [INFO], [INSTANCE], array indexing
    a[0] — does not match. No false positives.

Tightest possible scope: one signature line changed, no new dependencies,
Cargo.lock untouched.

Regression tests

New crates/injection-defense/tests/inst_delimiter_variants.rs, both directions:

  • inst_delimiter_variants_are_blocked[INST], [/INST], [[INST]],
    [ INST ], <s>[INST], <<SYS>>…<</SYS>> all → Block + DelimiterAbuse.
  • benign_bracketed_text_is_not_flagged[INSTALL], [INSTRUCTIONS],
    [INFO], a[0], [INST. of Tech], [instance] all → Allow, no
    DelimiterAbuse.

Verification (all green locally)

  • cargo test -p ardur-injection-defense — pass (incl. 2 new tests)
  • cargo test -p ardur-e2e-tests — pass
  • cargo clippy -p ardur-injection-defense --all-targets -- -D warnings — clean
  • cargo fmt --check — clean

Fixes #353

#353)

The delimiter_injection signature only matched the doubled [[INST]] and
<|im_start|>, so the real single-bracket [INST] / [/INST] Llama/Mistral
chat-template delimiter — the form an attacker actually uses to smuggle a
new turn/role — passed the filter unflagged.

Widen the regex to (?i)\[\s*/?\s*INST\s*\]|<\|im_start\|>|<</?SYS>>:
matches [INST], [/INST], the doubled [[INST]] and internal-whitespace forms,
plus the closely related Llama system delimiters <<SYS>> / <</SYS>>. Anchored
to exactly INST/SYS so [INSTALL], [INSTRUCTIONS], [INFO], a[0] do not match.

Add crates/injection-defense/tests/inst_delimiter_variants.rs covering both
directions: the [INST] variants are now blocked as DelimiterAbuse, and
representative benign bracketed text is not falsely flagged.

Fixes #353

Checkpoint: architect/sessions/fix-353-inst-delimiter/journal.md
Signed-off-by: GR <gnanirn@gmail.com>
Signed-off-by: Gnani Nutakki <gnani.nutakki@gmail.com>
@coderabbitai

coderabbitai Bot commented Jul 23, 2026

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on base/target branches other than the default branch.

Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro Plus

Run ID: 45be49fa-be66-4cc2-b18d-28f353865c0e

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch fix/353-inst-delimiter

Comment @coderabbitai help to get the list of available commands.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant