In a few years we're going to look at this problem the same way that we now look at SQL injections
---
RT @nearcyan
Indirect Prompt Injection: Turning Bing Chat into a Data Pirate
by modifying a website that bing chat reads alongside a user, the chat agent is able to have its goals modified by that site, unbeknownst to the user
demo: https://greshake.github.io/
arxiv: https://arxiv.org/abs/2302.12173
https://twitter.com/nearcyan/status/1630769218512904192