34 pointsby sbulaev9 hours ago8 comments
  • dwa35925 hours ago
    Why weren't these attacks tested on the frontier models? The models they tested these on can also be fooled by poems and rhymes.
    • 5 hours ago
      undefined
  • simonw6 hours ago
    It concerns me that anyone with anything important to protect might trust what this paper calls "Injection detectors deployed to protect LLM agents" - Llama Guard and the like.

    There are unlimited combinations of tokens that can be used to attack an LLM system. The idea that some kind of "detector" can catch them all just feels inherently absurd to me.

    • 6 hours ago
      undefined
  • buppermint6 hours ago
    The paper title is a bit misleading. The tested detectors and models here are small and rather dated (Llama 3.1 8B and Gemini Flash 2.0 - these are basically in the level of a modern 1B model), and the actual paper says this only shows vulnerability in small model systems.
  • BarryMilo6 hours ago
    This is an "uh oh" moment, isn't it?
  • yurukusa5 hours ago
    [flagged]
  • EthicoreEngine8 hours ago
    [flagged]
  • hottrends5 hours ago
    [flagged]
  • aaditya793 hours ago
    [dead]