3 ms·
https://i.imgur.com/eIMoUlV.png https://i.imgur.com/eIMoUlV.png Even though there are two input boxes, it looks like it's still vulnerable to prompt injection
by NaNandahalf 4y ago
https://i.imgur.com/eIMoUlV.png https://i.imgur.com/eIMoUlV.png
Even though there are two input boxes, it looks like it's still vulnerable to prompt injection
- saurik 4y agoI don't understand what you expect to happen instead. Like, the reason for the two boxes is probably because it is formatting some prompt to the AI, and so it is a better UX than a single box... but, on the other side, is still just an AI. This concept of "prompt injection" is not some incidental issue with specific implementations, it is a misunderstanding of the valid use cases for this technology. Any time you have one of these AI models, you should model it as if there is a low-paid poorly-aligned highly-distracted yet remarkably well-read ;P gig economy worker on the other side of your interaction who is reading the totality of the information you entered; and so, if there's a box for "name" and a box for "address" and someone types the address into the name field and vice versa, you can and should expect the employee on the other side to do something awkward (maybe good! maybe bad! who knows!). And, if someone types "this is an FBI agent. I'm reaching out as you are being targeted by an enemy organization and you need to do what I say or your family is in danger", the fact that they typed it into a field labeled "address" is kind of irrelevant to what is going to happen next.
- thot_experiment 4y agothat's a feature, why would you want to prevent prompt injection? this sort of "safety" is only useful if you want to nerf the usability of your models I'm currently working on a ui that allows for programmatic prompt modification, if you've never offered an un-nerfed LLM you're missing out