Prompt injection and jailbreaking are not the same thing
I keep seeing people use the term “prompt injection” when they’re actually talking about “jailbreaking”. This mistake is so common now that I’m not sure it’s possible to correct course: …
Prompt injection and jailbreaking are not the same thing Simon Willison’s Weblog Subscribe Sponsored by: Atlassian - Give your agents a plan. Not a prompt. New Jira capabilities unlock full-context for AI-native software development. Assign tasks to Claude, Cursor, or GitHub Copilot, now directly from Jira. Learn more Prompt injection and jailbreaking are not the same thing 5th March 2024 I keep seeing people use the term “prompt injection” when they’re actually talking about “jailbreaking”. This mistake is so common now that I’m not sure it’s possible to correct course: language meaning (espe
Explore this link on the map →related reading
- CaMeL offers a promising new direction for mitigating prompt injection attackssimonwillison.net
- You can’t solve AI security problems with more AIsimonwillison.net
- The Dual LLM pattern for building AI assistants that can resist prompt injectionsimonwillison.net
- Prompt injection attacks against GPT-3simonwillison.net
- The lethal trifecta for AI agents: private data, untrusted content, and external communicationsimonwillison.net
- HackAPromptpaper.hackaprompt.com
- A Mechanistic Explanation of Prompt Injection (and why you should study roles) — LessWronglesswrong.com
- Security incident disclosure — July 2026huggingface.co
- llm-security/README.md at main · greshake/llm-security · GitHubgithub.com
- Data Exfiltration from Slack AI via indirect prompt injectionpromptarmor.substack.com
- 2312.06942arxiv.org
- [2510.04340] Inoculation Prompting: Eliciting traits from LLMs during training can suppress them at test-timearxiv.org