Reverse Proxy GenAI Traffic Inspection for Prompt Injection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing cybersecurity solutions are ineffective in detecting and mitigating prompt injection attacks and data leaks in generative artificial intelligence (GenAI) traffic, leading to privacy and security concerns for enterprises and GenAI model developers.

Innovation Solution

A cloud-based network security system that uses machine learning models to classify GenAI requests and responses, applying relevant security policies to detect and prevent prompt injection attacks and data leaks, while efficiently generating training data for these models.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If existing cybersecurity solutions (WAF, IPS, DLP) are used for GenAI traffic inspection, then general security coverage is provided, but detection accuracy is poor with large numbers of false positives and false negatives

Engineering Contradiction:
Improvedetection accuracyVSAvoidfalse positive rate
Core Design Contradiction:
ReliabilityVSMeasurement precision

Solution Approach 1:

The patent changes the detection parameters from traditional cybersecurity patterns to GenAI-specific parameters including prompt injection patterns, system prompt structures, and training data characteristics. This allows accurate identification of malicious activities while reducing false positives by understanding the unique structure and behavior of GenAI traffic.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent introduces an intermediary GenAI traffic inspection system that sits between existing cybersecurity solutions and GenAI applications. This intermediary layer specifically handles GenAI traffic analysis using specialized techniques, while allowing traditional WAF, IPS, and DLP systems to continue operating without being overwhelmed by false positives.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If existing single-direction detection systems are used, then implementation simplicity is maintained, but comprehensive security coverage is lost as client-to-server and server-to-client traffic are not both analyzed

Engineering Contradiction:
Improvesecurity coverageVSAvoiddetection system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent creates a universal inspection system that handles both client-to-server requests and server-to-client responses through a single bidirectional analysis platform. The system inspects prompts sent to GenAI models and analyzes generated responses, providing comprehensive security coverage in both directions without requiring separate detection systems.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If traditional pattern matching and heuristics are used for attack identification, then existing security infrastructure is leveraged, but GenAI-specific attacks like prompt injection are not effectively detected

Engineering Contradiction:
Improveattack detection effectivenessVSAvoidGenAI attack coverage
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent changes the detection approach from traditional pattern matching to GenAI-specific parameter analysis including prompt injection patterns, system prompt structures, and training data characteristics. This enables effective detection of emerging GenAI attacks while maintaining the ability to handle traditional security threats.

Inventive Principle:
Principle #35Parameter changes

4Reliability

If comprehensive security inspection is implemented without optimization, then security thoroughness is maximized, but processing efficiency and speed are reduced

Engineering Contradiction:
Improvesecurity inspection thoroughnessVSAvoidtraffic processing speed
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent segments the security inspection process into distinct phases: request inspection for prompt injection detection, response inspection for data leak detection, and selective deep analysis based on risk assessment. This segmentation allows thorough security inspection while maintaining processing efficiency by applying comprehensive analysis only when necessary.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS12284222B1Security and privacy inspection of bidirectional generative artificial intelligence traffic using a reverse proxy
Publication Date: 2025.04.22 NETSKOPE INC
  • US12284222B1 patent drawing
  • US12284222B1 patent drawing
  • US12284222B1 patent drawing

AI summary

Disclosed is a cloud-based security system implemented in a reverse proxy that provides bidirectional traffic inspection to protect against privacy and security concerns related to the GenAI services. The security system intercepts requests directed to the GenAI service protected by the reverse proxy implementation of the network security system. The security system includes a GenAI request classifier trained to classify prompts submitted to the GenAI application as one of benign, prompt injection attack, or uploaded files. The security system further includes a GenAI response classifier trained to classify responses from the GenAI application as one of normal, leaked system prompt, leaked user uploaded files, or leaked training data. Based on the classification, and optionally other security analysis, the security system may enforce security policies on both the requests and responses that block the traffic, trigger alerts to administrators, and the like to enforce security and privacy protection on bidirectional traffic.