> 3-classifier ensemble + regex fallback blocks prompt injection in <7ms. DAN jailbreak, system extraction, and role override all detected at 0.98 confidence.
Using regular expressions to detect prompt injections is not a credible strategy.
arw0n•22 minutes ago
The sub-7ms on a classifier ensemble with 98% confidence in 3 categories makes me suspect these classifiers are confidently wrong.
Discussion (2 Comments)Read Original on HackerNews
Using regular expressions to detect prompt injections is not a credible strategy.