3 ms·
Especially with the rise of the idea of "GPT stores" to share custom GPTs, this becomes an even bigger issue with those kinds of integrations. One potential mi
by g_p 3y ago
Especially with the rise of the idea of "GPT stores" to share custom GPTs, this becomes an even bigger issue with those kinds of integrations.
One potential mitigation might be to require them to expose all "prompt" data and similar context as plain source users can see (which would effectively kill off commercialization, but allow users to see what the model was promoted to do).
We'll soon see attacks like SSRF/CSRF and similar play out in terms of asking a model to make a POST request containing user data, or rendering arbitrary JS (or putting arbitrary code into code a user is asking to have written).
I don't know if forcing the full prompt and context to be visible and open for scrutiny would help entirely, but it feels like it ought to start things off by at least helping users look for absolutely blatant issues in the prompting.
- j0hnyl 3y agoYes, however the visible prompt is only a small part of the big picture, because you don't know what's going on in the backend to augment the responses.