CaMeL offers a promising new direction for mitigating prompt injection attacks
In the two and a half years that we’ve been talking about prompt injection attacks I’ve seen alarmingly little progress towards a robust solution. The new paper Defeating Prompt Injections …
CaMeL offers a promising new direction for mitigating prompt injection attacks Simon Willison’s Weblog Subscribe Sponsored by: Microsoft - Agent projects stall between demo and production. Microsoft's MVP checklist closes that gap. Try it CaMeL offers a promising new direction for mitigating prompt injection attacks 11th April 2025 In the two and a half years that we’ve been talking about prompt injection attacks I’ve seen alarmingly little progress towards a robust solution. The new paper Defeating Prompt Injections by Design from Google DeepMind finally bucks that trend. This one is worth pa
saved by
related reading
- A Mechanistic Explanation of Prompt Injection (and why you should study roles) — LessWronglesswrong.com
- The lethal trifecta for AI agents: private data, untrusted content, and external communicationsimonwillison.net
- The Dual LLM pattern for building AI assistants that can resist prompt injectionsimonwillison.net
- Prompt Injection as Role Confusionrole-confusion.github.io
- 2025: The year in LLMssimonwillison.net
- llm-security/README.md at main · greshake/llm-securitygithub.com
- Prompt injection and jailbreaking are not the same thingsimonwillison.net
- You can’t solve AI security problems with more AIsimonwillison.net
- [2603.12277] Prompt Injection as Role Confusionarxiv.org
- [2401.05566] Sleeper Agents: Training Deceptive LLMs that Persist Through Safety Trainingarxiv.org
- What We’ve Learned From A Year of Building with LLMs – Applied LLMsapplied-llms.org
- GitHub - brexhq/prompt-engineering: Tips and tricks for working with Large Language Models like OpenAI's GPT-4.github.com