Hacker Newsnew | past | comments | ask | show | jobs | submitlogin
Prompt injection is not SQL injection (it may be worse) (ncsc.gov.uk)
2 points by giuliomagnifico 15 days ago | hide | past | favorite | 1 comment


The SQL injection analogy breaks down because LLMs don’t have a fixed execution grammar.

Treating prompts as untrusted input streams rather than instructions helped us reason about the problem more clearly, especially for production systems.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: