The malicious text can come directly from a user or indirectly from documents, webpages, emails, and tool output. Applications must separate data from instructions and enforce authorization outside the model.
Prompt injection is an attack in which untrusted content attempts to override instructions or manipulate a model's actions.
The malicious text can come directly from a user or indirectly from documents, webpages, emails, and tool output. Applications must separate data from instructions and enforce authorization outside the model.