So, this is a way I think we might not be completely stopping injection or indirect prompt injection, which again we did quite a bit and also pioneered at the beginning of the year. But at least we can detect once something is interpreted as an instruction block instead of a data block. So, at least we can’t prevent bad things from happening, but we can detect it and then basically stop there and basically reset, so to say. So, I think that’s at least our current strategies where we have some hope. Otherwise, I think it’s pretty difficult.

Keyboard shortcuts

j previous speech k next speech