
- UK’s NCSC warns prompt injection attacks may never be fully mitigated due to LLM design
- Unlike SQL injection, LLMs lack separation between instructions and data, making them inherently vulnerable
- Developers urged to treat LLMs as “confusable deputies” and design systems that limit compromised outputs
Prompt injection attacks, meaning attempts to manipulate a large language model (LLM) by embedding hidden or malicious instructions inside user-provided content, might never be properly mitigated.