Prompt injection and jailbreaking are not the same thing
I keep seeing people use the term “prompt injection” when they’re actually talking about “jailbreaking”. This mistake is so common now that I’m not sure it’s possible to correct course: …
Prompt injection and jailbreaking are not the same thing Simon Willison’s Weblog Subscribe Sponsored by: Atlassian - Give your agents a plan. Not a prompt. New Jira capabilities unlock full-context for AI-native software development. Assign tasks to Claude, Cursor, or GitHub Copilot, now directly from Jira. Learn more Prompt injection and jailbreaking are not the same thing 5th March 2024 I keep seeing people use the term “prompt injection” when they’re actually talking about “jailbreaking”. This mistake is so common now that I’m not sure it’s possible to correct course: language meaning (espe
related reading
- CaMeL offers a promising new direction for mitigating prompt injection attackssimonwillison.net
- A Mechanistic Explanation of Prompt Injection (and why you should study roles) — LessWronglesswrong.com
- You can’t solve AI security problems with more AIsimonwillison.net
- Prompt Injection as Role Confusionrole-confusion.github.io
- llm-security/README.md at main · greshake/llm-securitygithub.com
- The lethal trifecta for AI agents: private data, untrusted content, and external communicationsimonwillison.net
- The Dual LLM pattern for building AI assistants that can resist prompt injectionsimonwillison.net
- Prompt injection attacks against GPT-3simonwillison.net
- GitHub - brexhq/prompt-engineering: Tips and tricks for working with Large Language Models like OpenAI's GPT-4.github.com
- HackAPromptpaper.hackaprompt.com
- Prompt Engineering Guide | Prompt Engineering Guidepromptingguide.ai
- [2603.12277] Prompt Injection as Role Confusionarxiv.org