Didn't read through the whole thing yet, but this seems to be the key idea:
"With LLM-integrated applications, adversaries
could control the LLM, without direct access, by indirectly
injecting it with prompts placed within sources retrieved at
inference time."
Comments
Didn't read through the whole thing yet, but this seems to be the key idea:
"With LLM-integrated applications, adversaries could control the LLM, without direct access, by indirectly injecting it with prompts placed within sources retrieved at inference time."