{"repo":"tldrsec/prompt-injection-defenses","free":true,"listed":false,"github":"https://github.com/tldrsec/prompt-injection-defenses","clone":"git clone https://github.com/tldrsec/prompt-injection-defenses.git","description":"Every practical and proposed defense against prompt injection.","language":null,"stars":724,"topics":["ai","cybersecurity","prompt-injection","security"],"license":null,"category":"security-tools","readme_excerpt":"prompt-injection-defenses This repository centralizes and summarizes practical and proposed defenses against prompt injection. Table of Contents - prompt-injection-defenses - Table of Contents - Blast Radius Reduction - Input Pre-processing (Paraphrasing, Retokenization) - Guardrails \\& Overseers, Firewalls \\& Filters - Taint Tracking - Secure Threads / Dual LLM - Ensemble Decisions / Mixture of Experts - Prompt Engineering / Instructional Defense - Robustness, Finetuning, etc - Preflight \"injection test\" - Tools - References - Papers - Critiques of Controls Blast Radius Reduction Reduce the impact of a successful prompt injection through defensive design. Summary -------- ------- Recommendations to help mitigate prompt injection: limit the blast radius I think you need to develop software with the assumption that this issue isn’t fixed now and won’t be fixed for the foreseeable future, which means you have to assume that if there is a way that an attacker could get their untrusted text into your system, they will be able to subvert your instructions and they will be able to trigger any sort of actions that you’ve made available to your model. This requires very careful security thinking. You need everyone involved in designing the system to be on board with this as a threat, because you really have to red team this stuff. You have to think very hard about what could go wrong, and make sure that you’re limiting that blast radius as much as possible. Securing LLM Systems Again","default_branch":null,"files":null,"tree":[],"storefront":"/r/tldrsec","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/tldrsec/prompt-injection-defenses/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}