5 ms·
How would you go about making it more secure but still getting to have your cake too? Off the top my head, could you: a) only ingest text that can be OCRd or so
by afarviral 1y ago
How would you go about making it more secure but still getting to have your cake too? Off the top my head, could you: a) only ingest text that can be OCRd or somehow determine if it is human readable b) make it so text from the web session is isolated from the model with respect to triggering an action. Then it's simply a tradeoff at that point.
- kccqzy 1y agoI think Simon has proposed breaking the lethal trifecta by having two LLMs, where the first has access to untrusted data but cannot do any actions, and the second LLM has privileges but only abstract variables from the first LLM not the content. See https://simonwillison.net/2023/Apr/25/dual-llm-pattern/ https://simonwillison.net/2023/Apr/25/dual-llm-pattern/ It is rather similar to your option (b).
- maximilianthe1 1y agoCan't the attacker then jailbreak the first LLM to generate jailbreak with actions for the second one?
- arthurcolle 1y agoYes they can
- dfabulich 1y agoIf you read the fine article, you'll see that the approach includes a non-LLM controller managing structured communication between the Privileged LLM (allowed to perform actions) and the Quarantined LLM (only allowed to produce structured data, which is assumed to be tainted). See also CaMeL https://simonwillison.net/2025/Apr/11/camel/ https://simonwillison.net/2025/Apr/11/camel/ which incorporates a type system to track tainted data from the Quarantined LLM, ensuring that the Privileged LLM can't even see tainted _data_ until it's been reviewed by a human user. (But this can induce user fatigue as the user is forced to manually approve all the data that the Privileged LLM can access.)
- yencabulator 1y ago"Structured data" is kind of the wrong description for what Simon proposes. JSON is structured but can smuggle a string with the attack inside it. Simon's proposal is smarter than that.
- j45 1y agoOne would have to be relatively invisible. Non-deterministic security feels like a relatively new area.
- pishpash 1y agoThat's just an information bottleneck. It doesn't fundamentally change anything.
- jimbokun 1y agoI don't believe it's possible to give an LLM full access to your browser in a safe way at this point in time. There will need to be new and novel innovations to make that combination safe.
- brookst 1y agoIs it possible to give your parents access to to your browser in a safe way?
- seemaze 1y agoThat’s easy. Giving my parents a safe browser to utilize without me is the challenge.
- zwnow 1y agoBecause there never were safe web browsers in the first place. The internet is fundamentally flawed and programmers are continously having to invent coping mechanisms to the underlying issue. This will never change.
- nertirs1 1y agoYou seem like the guy, who would call car airbags a coping mechanism.
- seattle_spring 1y agoHe's off in another thread calling people "weak" and laughing at them for taking pain relievers to help with headaches.
- Arisaka1 1y agoJust because you can never have absolute safety and security doesn't mean that you should be deliberately introduce more vulnerabilities in a system. It doesn't mtif we're talking about operating systems or the browser itself. We shouldn't be sacrificing every trade-off indiscriminately out of fear of being left behind in the "AI world".
- csomar 1y agoIn the future, any action with consequence will require crypto-withdrawal levels of security. Maybe even a face scan before you can complete it.
- ares623 1y agoAhh technology. The cause of, and _solution to_, all of life’s problems.
- deleted 1y ago[deleted]