The Dual LLM pattern for building AI assistants that can resist prompt injection
I really want an AI assistant: a Large Language Model powered chatbot that can answer questions and perform actions for me based on access to my private data and tools. …
The Dual LLM pattern for building AI assistants that can resist prompt injection Simon Willison’s Weblog Subscribe Sponsored by: Atlassian - Give your agents a plan. Not a prompt. New Jira capabilities unlock full-context for AI-native software development. Assign tasks to Claude, Cursor, or GitHub Copilot, now directly from Jira. Learn more The Dual LLM pattern for building AI assistants that can resist prompt injection 25th April 2023 I really want an AI assistant: a Large Language Model powered chatbot that can answer questions and perform actions for me based on access to my private data a
Explore this link on the map →related reading
- The lethal trifecta for AI agents: private data, untrusted content, and external communicationsimonwillison.net
- CaMeL offers a promising new direction for mitigating prompt injection attackssimonwillison.net
- LLM Powered Autonomous Agents | Lil'Loglilianweng.github.io
- Guardian Angels: LLM Personalization for Productivity and Security · Gwern.netgwern.net
- You can’t solve AI security problems with more AIsimonwillison.net
- Data Exfiltration from Slack AI via indirect prompt injectionpromptarmor.substack.com
- Prompt injection and jailbreaking are not the same thingsimonwillison.net
- HackAPromptpaper.hackaprompt.com
- llm-security/README.md at main · greshake/llm-security · GitHubgithub.com
- A Mechanistic Explanation of Prompt Injection (and why you should study roles) — LessWronglesswrong.com
- Building Effective AI Agents \ Anthropicanthropic.com
- [2603.12277] Prompt Injection as Role Confusionarxiv.org