| ▲ | cyanregiment 3 hours ago | |
I am surprised to not see more literature on how LLMs are layered to handle complex decision making including security. I’m assuming most companies aren’t just routing user prompts/file uploads to a single LLM and returning the reply back hahah Even file uploads - I would strip content and only support certain file types. The stripped text would be analyzed. There wouldn’t be a concept of “hidden text” since it’s not going through a vision model. It’s just text. The threat is the same as any other prompt injection. Hiding the text in the document would have no additional effect. | ||