7 comments

  • dwa3592 36 minutes ago
    Why weren't these attacks tested on the frontier models? The models they tested these on can also be fooled by poems and rhymes.
  • buppermint 1 hour ago
    The paper title is a bit misleading. The tested detectors and models here are small and rather dated (Llama 3.1 8B and Gemini Flash 2.0 - these are basically in the level of a modern 1B model), and the actual paper says this only shows vulnerability in small model systems.
  • simonw 1 hour ago
    It concerns me that anyone with anything important to protect might trust what this paper calls "Injection detectors deployed to protect LLM agents" - Llama Guard and the like.

    There are unlimited combinations of tokens that can be used to attack an LLM system. The idea that some kind of "detector" can catch them all just feels inherently absurd to me.

  • BarryMilo 1 hour ago
    This is an "uh oh" moment, isn't it?
  • yurukusa 12 minutes ago
    [flagged]
  • hottrends 42 minutes ago
    [flagged]
  • EthicoreEngine 3 hours ago
    [flagged]