---
格式版本: 2
标题: "Reflex-Guard: A Low-Latency Guardrail for LLM Prompt Safety Using Dense Semantic Embeddings"
原文链接: "https://arxiv.org/abs/2608.17556"
发布日期: "2026-08-18"
发布时间校准状态: "found"
发布时间需复核: "否"
发布时间来源: "rule:local:strict_original_body"
发布时间证据: "**\\[v1\\]** Tue, 18 Aug 2026 09:19:22 UTC (2,747 KB)"
发布时间校准原因: "规则确认唯一严格发布时间，来源 local:strict_original_body"
发布时间校准置信度: "high"
发布时间候选数量: 18
发布时间严格候选数量: 6
发布时间原页读取状态: "source template page reused from URL open"
发布时间未找到原因: ""
发布时间校准时间: "2026-08-20T15:39:00+08:00"
发布时间仲裁状态: "skipped"
发布时间仲裁尝试次数: 0
发布时间仲裁耗时毫秒: 0
发现时间: "2026-08-20T15:33:55+08:00"
入库时间: "2026-08-20T07:39:00.216Z"
来源平台: "arXiv 学术论文搜索"
搜索渠道: "source_template"
搜索词: "https://arxiv.org/search/?query=latency&searchtype=all"
匹配关键词:
  - "latency"
  - "deployment"
相关厂家:
  []
相关专家:
  []
内容类型: "网页"
抓取工具: "Free Fetch + Defuddle"
清洗工具: "Defuddle Markdown + Defuddle/Readability 正文提取"
原始附件:
  []
AI优质: "否"
AI打分: 2
AI分档: "非优质"
AI质检状态: "不通过"
AI打分理由: "该论文为LLM提示安全防护研究，与超节点/AI Rack/机柜级AI基础设施及其关键部件、供电、液冷、互连等主题完全无关，仅命中通用词latency，不构成有效信号。"
AI质检模型: "ali-deepseek-v4-flash"
AI质检时间: "2026-08-20T15:42:41+08:00"
AI主题相关性: 0
AI来源权威性: 2
AI新颖性: 0
AI技术细节: 0
AI商业部署信号: 0
AI完整性: 0
AI摘要: "Reflex-Guard 是一个本地运行的轻量级 LLM 提示安全过滤方案，结合越狱预处理、句向量嵌入和七个二分类器，在 37.6 毫秒端到端延迟下对有害提示达到 95.9% 召回率。"
AI摘要模型: "ali-deepseek-v4-flash"
AI摘要时间: "2026-09-07T03:22:30.481Z"
采集批次: "2026年8月20日14点19分32秒"
采集批次ID: "20260820-141932-079"
去重键: "https://arxiv.org/abs/2608.17556"
---

## Computer Science > Cryptography and Security

## Title:Reflex-Guard: A Low-Latency Guardrail for LLM Prompt Safety Using Dense Semantic Embeddings

[View PDF](https://arxiv.org/pdf/2608.17556) [HTML (experimental)](https://arxiv.org/html/2608.17556v1)

> Abstract:Large Language Models (LLMs) in real-world applications often face the risks of specially crafted prompts designed to bypass the safety controls. Existing guardrail methods, such as LLM-as-a-judge and cloud-based safety APIs are able to detect unsafe content. However, they often add a delay of about 250-900 ms to each request. This delay is too high for real-time applications, when the system usually needs to respond in less than 100 ms. Furthermore, routing user prompts through external moderation endpoints raises significant data privacy concerns. This paper introduces Reflex-Guard, a lightweight guardrail that runs locally. It uses jailbreak-aware preprocessing, compact sentence-transformer embeddings, and seven fast binary classifiers. Together, these components enable high-accuracy prompt safety filtering with much lower latency than existing solutions. Through systematic evaluation on a strategically balanced dataset of 30,568 samples drawn from five complementary sources, we demonstrate that Reflex-Guard achieves 95.9% recall on harmful prompts at 37.6 ms end-to-end latency. It is faster than existing baselines, including Llama Guard 2 at 255 ms and SafeDecoding at 723 ms. It can detect 100% of GCG suffix attacks and Base64-encoded prompts using the default threshold. However, DrAttack structured prompts required lowering the threshold to 0.03 for optimal detection, as they produced a distinct probability distribution. Reflex-Guard achieves Reflex Efficiency Score (RES) scores up to 16.79, significantly outperforming Llama Guard 2 (11.90) and SafeDecoding (9.80). This analysis offers practical deployment advice and shows that different attack types occupy distinct regions in the embedding probability space.

| Subjects: | Cryptography and Security (cs.CR); Computation and Language (cs.CL); Machine Learning (cs.LG) |
| --- | --- |
| Cite as: | [arXiv:2608.17556](https://arxiv.org/abs/2608.17556) \[cs.CR\] |
|  | (or [arXiv:2608.17556v1](https://arxiv.org/abs/2608.17556v1) \[cs.CR\] for this version) |
|  | [https://doi.org/10.48550/arXiv.2608.17556](https://doi.org/10.48550/arXiv.2608.17556) |

## Submission history

From: Ranat Das Prangon \[[view email](https://arxiv.org/show-email/277d6a51/2608.17556)\]  
**\[v1\]** Tue, 18 Aug 2026 09:19:22 UTC (2,747 KB)

[Which authors of this paper are endorsers?](https://arxiv.org/auth/show-endorsers/2608.17556) | Disable MathJax ([What is MathJax?](https://info.arxiv.org/help/mathjax.html))
