This study evaluates three prompt-injection detectors under a frozen-threshold, deployment-aware setting.
It measures robustness across source shift, hard-benign prompts, and successful JailbreakBench artifacts without threshold retuning.
The results show substantial variation in recall, false-positive behavior, and cross-threat transfer across detectors.
The study also highlights deployment trade-offs through prevalence-aware precision, latency, and decision-margin analysis.
