IDEAS home Printed from https://ideas.repec.org/a/gam/jftint/v18y2026i5p252-d1938923.html

Evaluation of NeMo Guardrails as a Firewall for User–LLM Interaction

Author

Listed:
  • Antônio João Azambuja

    (Department of Space Sciences and Technologies, Aeronautics Institute of Technology (ITA), São José dos Campos 12228-900, Brazil)

  • Marcos Guilherme

    (Institute of Informatics, Federal University of Goiás (UFG), Goiânia 74690-900, Brazil)

  • João Victor Fernandes de Castro

    (Institute of Informatics, Federal University of Goiás (UFG), Goiânia 74690-900, Brazil)

  • Jean Phelipe de Oliveira Lima

    (Department of Aeronautical Infrastructure Engineering, Aeronautics Institute of Technology (ITA), São José dos Campos 12228-900, Brazil)

  • Leonardo B. Oliveira

    (Department of Computer Science, Federal University of Minas Gerais (UFMG), Belo Horizonte 31270-901, Brazil)

  • Anderson da Silva Soares

    (Institute of Informatics, Federal University of Goiás (UFG), Goiânia 74690-900, Brazil)

Abstract

The rapid integration of Large Language Models (LLMs) into critical personal and professional environments has exacerbated security risks, particularly adversarial attacks such as prompt injection and jailbreaking, which aim to bypass safety alignment. This study evaluates the efficacy of NVIDIA’s Llama-3.1-nemoguard-8b-content-safety model acting as a semantic firewall to mitigate these threats. To ensure a robust assessment, we utilized the ‘Do Not Answer’ dataset, augmented with 939 synthetically generated benign prompts to create a balanced corpus of 1878 samples. The evaluation methodology encompasses a risk-category analysis, standard binary classification metrics, and a novel metric, the Compensation Rate, which measures the firewall’s ability to block responses when the underlying LLM fails. Results indicate a high Precision (94.57%) but a moderate Sensitivity (51.97%), uncovering a critical performance trade-off: the model exhibits a conservative bias, prioritizing high precision to minimize false positives at the expense of recall for nuanced adversarial prompts, particularly in categories involving sensitive data leakage and misinformation. Furthermore, the proposed Compensation Rate achieved 34.8%, suggesting that the semantic firewall successfully mitigated 34.8% of instances where the foundational LLM’s internal safety alignment failed. These findings indicate that while the system effectively blocks explicit threats, its efficacy as a secondary defense diminishes against context-dependent vulnerabilities, notably data exfiltration and misinformation.

Suggested Citation

  • Antônio João Azambuja & Marcos Guilherme & João Victor Fernandes de Castro & Jean Phelipe de Oliveira Lima & Leonardo B. Oliveira & Anderson da Silva Soares, 2026. "Evaluation of NeMo Guardrails as a Firewall for User–LLM Interaction," Future Internet, MDPI, vol. 18(5), pages 1-21, May.
  • Handle: RePEc:gam:jftint:v:18:y:2026:i:5:p:252-:d:1938923
    as

    Download full text from publisher

    File URL: https://www.mdpi.com/1999-5903/18/5/252/pdf
    Download Restriction: no

    File URL: https://www.mdpi.com/1999-5903/18/5/252/
    Download Restriction: no
    ---><---

    More about this item

    Keywords

    ;
    ;
    ;
    ;

    Statistics

    Access and download statistics

    Corrections

    All material on this site has been provided by the respective publishers and authors. You can help correct errors and omissions. When requesting a correction, please mention this item's handle: RePEc:gam:jftint:v:18:y:2026:i:5:p:252-:d:1938923. See general information about how to correct material in RePEc.

    If you have authored this item and are not yet registered with RePEc, we encourage you to do it here. This allows to link your profile to this item. It also allows you to accept potential citations to this item that we are uncertain about.

    We have no bibliographic references for this item. You can help adding them by using this form .

    If you know of missing items citing this one, you can help us creating those links by adding the relevant references in the same way as above, for each refering item. If you are a registered author of this item, you may also want to check the "citations" tab in your RePEc Author Service profile, as there may be some citations waiting for confirmation.

    For technical questions regarding this item, or to correct its authors, title, abstract, bibliographic or download information, contact: MDPI Indexing Manager The email address of this maintainer does not seem to be valid anymore. Please ask MDPI Indexing Manager to update the entry or send us the correct address (email available below). General contact details of provider: https://www.mdpi.com .

    Please note that corrections may take a couple of weeks to filter through the various RePEc services.

    IDEAS is a RePEc service. RePEc uses bibliographic data supplied by the respective publishers.