arXiv · 2507.23453
Counterfactual Evaluation for Blind Attack Detection in LLM-based Evaluation Systems
Abstract
This paper investigates defenses for LLM-based evaluation systems against prompt injection. We formalize a class of threats called blind attacks, where a candidate answer is crafted independently of the true answer to deceive the evaluator. To counter such attacks, we propose a framework that augments Standard Evaluation (SE) with Counterfactual Evaluation (CFE), which re-evaluates the submission against a deliberately false ground-truth answer. An attack is detected if the system validates an answer under both standard and counterfactual conditions. Experiments show that while standard evaluation is highly vulnerable, our SE+CFE framework significantly improves security by boosting attack detection with minimal performance trade-offs.
Explore related subjects
Keep this discovery
Lijia Liu, Takumi Kondo, Kyohei Atarashi, Koh Takeuchi, Jiyi Li, Shigeru Saito, Hisashi Kashima. 2025-07-31. Counterfactual Evaluation for Blind Attack Detection in LLM-based Evaluation Systems. https://arxiv.org/abs/2507.23453
Cite the original work for its findings. Save a collection to share your selection of sources.