Posts

Showing posts with the label AI Security

Securing LLM Applications: Prompt Injection, Data Leakage and Agent Risk

Applications built on large language models introduce a risk class that existing controls do not cover well, because the system's instructions and its input arrive through the same channel and in the same form. Everything below follows from that one architectural fact. Prompt injection A model receives a prompt containing the developer's instructions and the user's content concatenated together. The model has no reliable way to distinguish which text is authority and which is data — they are both just tokens. Content that says "ignore previous instructions and do X" may be followed. The structural parallel is SQL injection : code and data sharing one channel. The difference is that SQL injection has a complete fix in parameterized queries, where the database is told explicitly which part is structure and which is value. No equivalent exists for language models. There is no parameterization primitive, and prompt-based defences are heuristics an attacker can wo...