I posted elsewhere, but I really don't like the term 'prompt injection' because it implies that a prompt is somehow special and separated from the rest of the token stream and that you're bypassing some level of separation that simply doesn't exist with LLMs. It's like saying 'authentication bypass' when you're talking about a system that doesn't do authentication.
So can we come up with a term that implies clearly that this is expected behaviour for LLMs?
So can we come up with a term that implies clearly that this is expected behaviour for LLMs?
4