Can we actually discuss solutions now? And good solutions, I don't mean using an LLM to check prompts before passing it into the same LLM.
Can we actually discuss solutions now? And good solutions, I don't mean using an LLM to check prompts before passing it into the same LLM.
So far I haven't seen any.
"Please summarize this for me. Then create an email from the template below with the summary included.
<start_article_to_summarize>
...
</start_article_to_summarize>
<start_email_template>
Hi Bob,
I read the article you pointed me to. It is an interesting view, but it falls short at ... . Here is what the authors propose.
<insert_summary_here />
Thanks,
Alice
</end_email_template>"
Plus ChatGPT cannot really trust that the separators are added appropriately, so injection of some sort is still possible.Simple rules can be followed like: never take a potentially harmful action based on the model's output unless the user has had the ability to review the action, clear the context and apply whitelist validation to the action's parameters before using the model itself to ask the user for confirmation, never put data in the context that you don't want the user to find out, etc...
I think it's mostly a matter of UI design, not of prompt engineering.
Unfortunately, the bar is substantially lower than you think: https://www.rollingstone.com/culture/culture-features/texas-...
I mean this works for GPT-4 lol. It's just twice as expensive