Skip to main navigation Skip to search Skip to main content

Promptshield: Policy-Aware DLP Framework for Generative Al Prompts

  • Istanbul Technical University

Research output: Contribution to journalConference articlepeer-review

Abstract

The increasing use of generative AI tools in the workplace raises significant concerns about inadvertent data leakage through employee-generated prompts. As organizations begin to explore layered protections for AI interactions, existing approaches remain limited in their ability to provide customizable, context-aware controls at the prompt level. In this paper, we propose PromptShield, a policy-aware framework designed to prevent sensitive data exposure before prompts are submitted to large language models (LLMs). Unlike traditional data loss prevention (DLP) systems, PromptShield offers real-time, contextual prompt classification, role-based policy enforcement, and an optional human-in-the-loop redaction layer. We simulate diverse enterprise roles (e.g., HR, Finance, R&D), generate a 900-prompt labeled synthetic dataset, and evaluate the framework's generalization on an independent 435-prompt test set. Our results demonstrate the feasibility of proactive user-side DLP in generative AI interactions, achieving 72.92% accuracy on previously unseen prompts and addressing a critical and emerging challenge in enterprise data security.

Original languageEnglish
Pages (from-to)1537-1542
Number of pages6
JournalInternational Conference on Computer Science and Engineering, UBMK
Issue number2025
DOIs
Publication statusPublished - 2025
Event10th International Conference on Computer Science and Engineering, UBMK 2025 - Istanbul, Turkey
Duration: 17 Sept 202521 Sept 2025

Bibliographical note

Publisher Copyright:
© 2025 IEEE.

Keywords

  • AI Security
  • Data Security
  • DLP
  • Generative AI
  • Privacy

Fingerprint

Dive into the research topics of 'Promptshield: Policy-Aware DLP Framework for Generative Al Prompts'. Together they form a unique fingerprint.

Cite this