CaMeL offers a promising new direction for mitigating prompt injection attacks
In the two and a half years that we’ve been talking about prompt injection attacks I’ve seen alarmingly little progress towards a robust solution. The new paper Defeating Prompt Injections …
CaMeL offers a promising new direction for mitigating prompt injection attacks Simon Willison’s Weblog Subscribe Sponsored by: Microsoft - Agent projects stall between demo and production. Microsoft's MVP checklist closes that gap. Try it CaMeL offers a promising new direction for mitigating prompt injection attacks 11th April 2025 In the two and a half years that we’ve been talking about prompt injection attacks I’ve seen alarmingly little progress towards a robust solution. The new paper Defeating Prompt Injections by Design from Google DeepMind finally bucks that trend. This one is worth pa
Explore this link on the map →saved by
related reading
- Probe-Based Data Attribution: Surfacing and Mitigating Undesirable Behaviors in LLM Post-Traininggoodfire.ai
- 2025: The year in LLMssimonwillison.net
- The Dual LLM pattern for building AI assistants that can resist prompt injectionsimonwillison.net
- The lethal trifecta for AI agents: private data, untrusted content, and external communicationsimonwillison.net
- Prompt injection and jailbreaking are not the same thingsimonwillison.net
- You can’t solve AI security problems with more AIsimonwillison.net
- A Mechanistic Explanation of Prompt Injection (and why you should study roles) — LessWronglesswrong.com
- [2603.12277] Prompt Injection as Role Confusionarxiv.org
- Guardian Angels: LLM Personalization for Productivity and Security · Gwern.netgwern.net
- HackAPromptpaper.hackaprompt.com
- llm-security/README.md at main · greshake/llm-security · GitHubgithub.com
- [2401.05566] Sleeper Agents: Training Deceptive LLMs that Persist Through Safety Trainingarxiv.org