4 ms·
The mitigation for sql injection attacks is to parameterize your queries- in other words, separating the “program” (the sql query syntax) from the “data” (the p
by ipython 3y ago
The mitigation for sql injection attacks is to parameterize your queries- in other words, separating the “program” (the sql query syntax) from the “data” (the parameters to the sql query)
I am unaware of a similar mechanism for llms. Anthropic’s documentation talks about using xml tags to separate parts of a prompt, which sounds promising. However I’m not clear if that is really triggering a deterministic process in the llm to process that data differently, or if it’s just another “hint” to a non deterministic model.
Curious to hear from folks way more experienced than I am on this topic.
- liampulles 3y agoIf the source of data used to build the prompt does not allow for any user provided free text, then it's fine. This restricts what kind of thing your UI form can do obviously.
- joshspankit 3y agoOpenAI is working on this exact thing for this exact reason.
- ipython 3y agoAre there public references/resources with more information? Would love to learn more
- nonfamous 3y agoIn the OpenAI models the "system prompt", a separate prompt intended to control the LLM's behavior and not intended to be responded to directly, it meant for this purpose. It's not perfect, but I imagine OpenAI is working to improve that.
- deleted 3y ago[deleted]