4 ms·
How is the second LLM not also vulnerable from prompt injection? In order to supervise the first, it must receive data (presumably output from the first LLM?).
by snailmailman 4mo ago
How is the second LLM not also vulnerable from prompt injection? In order to supervise the first, it must receive data (presumably output from the first LLM?). All generated output after the user input is in the context should be considered possibly compromised/prompt injected. Having a second LLM just adds more obfuscation, but prompt injection could be chained.
- tweetle_beetle 4mo agoQuis custodiet ipsos custodes?
- j_w 4mo agoThat's when you bust out the third LLM. Nobody expects the fourth LLM to be the REAL LLM in the chain.
- vrighter 4mo agothe real llm is the friends we make along the way!