Optimize your guardrail policy against attacks the way you'd optimize a model against a loss
In many working environments, fine-tuning a model simply is not an option. The model may be hosted or provided by a third party, or the cost, complexity, and governance requirements of retraining may rule it out.