Historical milestone · 2025
CaMeL
Reviewed through September 18, 2026
2025 · Historical milestone
CaMeL
- Era
- 2020s
- Theme
- Safety, security & alignment
- Evidence form
- Preprint + AgentDojo evaluation
- School / paradigm
- Information-flow security / agent control
- Institution / context
- Google DeepMind
- Researchers
- Edoardo Debenedetti; collaborators
Understand
Plain-language record, transferred from the reviewed source module.
Theory or experimental setup. Separated control instructions from untrusted data and applied information-flow constraints and capabilities to tool-using language-model agents.
Result / historical claim. Reported meaningful prompt-injection resistance while retaining useful task completion on a bounded benchmark.
Apply
Professional implication, only where the reviewed record states one.
The checked-in record does not state a separate professional application for this entry. The topic page places it in the wider research lineage: Safety, security, and alignment.
Verify
Evidence status, stated limitations, and the external sources this record actually carries.
Evidence form. Preprint + AgentDojo evaluation
Limitation / debate. Deployment requires formal task policies and does not remove availability, base-model, side-channel, or integration failures.
Source status. The source link below is the verified link our reviewed topic research already carries for this milestone.
Reproduce
A reproduction tutorial is linked only when one exists for this exact record.
A reproduction tutorial is not yet available for this entry. The closest reviewed material is Safety, security, and alignment.
Cite or share
APA-like: This historical record carries a year only, and no author or publisher of record in the checked-in data. An APA reference would have to invent that metadata.
BibTeX: BibTeX requires an author and publication venue. Historical lineage entries store a narrative record and its source link, not structured authorship, so the field would be fabricated.
