The Dual LLM pattern for building AI assistants that can resist prompt injection
I really want an AI assistant: a Large Language Model powered chatbot that can answer questions and perform actions for me based on access to my private data and tools. …
The Dual LLM pattern for building AI assistants that can resist prompt injection Simon Willison’s Weblog Subscribe Sponsored by: Atlassian - Give your agents a plan. Not a prompt. New Jira capabilities unlock full-context for AI-native software development. Assign tasks to Claude, Cursor, or GitHub Copilot, now directly from Jira. Learn more The Dual LLM pattern for building AI assistants that can resist prompt injection 25th April 2023 I really want an AI assistant: a Large Language Model powered chatbot that can answer questions and perform actions for me based on access to my private data a
related reading
- The lethal trifecta for AI agents: private data, untrusted content, and external communicationsimonwillison.net
- CaMeL offers a promising new direction for mitigating prompt injection attackssimonwillison.net
- A Mechanistic Explanation of Prompt Injection (and why you should study roles) — LessWronglesswrong.com
- llm-security/README.md at main · greshake/llm-securitygithub.com
- Prompt Injection as Role Confusionrole-confusion.github.io
- Guardian Angels: LLM Personalization for Productivity and Security · Gwern.netgwern.net
- You can’t solve AI security problems with more AIsimonwillison.net
- LLM Powered Autonomous Agents | Lil'Loglilianweng.github.io
- [2603.12277] Prompt Injection as Role Confusionarxiv.org
- GitHub - brexhq/prompt-engineering: Tips and tricks for working with Large Language Models like OpenAI's GPT-4.github.com
- Data Exfiltration from Slack AI via indirect prompt injectionpromptarmor.substack.com
- What We’ve Learned From A Year of Building with LLMs – Applied LLMsapplied-llms.org