#LLMs violate the separation of instructions from data
https://www.ncsc.gov.uk/blog-post/prompt-injection-is-not-sql-injection
There are crucial differences between prompt and SQL injection which – if not considered – can undermine mitigations.
www.ncsc.gov.uk
Andrew Gallagher