ooh this is a dense and useful paper. i like that they took the time to apply it to a bunch of case studies and its all in 30 pages. i think basically all of them involve reducing the "agency" of the agents though - which is a fine tradeoff - but i think one should be aware that the Big Model folks dont try to engineer any of these and just collect data to keep reducing injection risk. the tradeoff of capability maxx…
Yeah, this paper is refreshingly conservative and practical: it takes the position that robust protection against prompt injection requires very painful trade-offs: These patterns impose intentional constraints on agents, explicitly limiting their ability to perform arbitrary tasks. That's a bucket of cold water in a lot of things people are trying to build. I imagine a lot of people will ignore this advice!
Re: Design Patterns for Securing LLM Agents Against Prompt Injections
#31yes agree most hype around agents is around stuff that ignore these patterns