Join the discussion
Write your take first — we'll ask for email only when you're ready to publish.
- Hacker News
- malware is a malicious program , it can be in memory even within another process but essentially its a little program of itself.
prompt injection is more close to an exploit. a sequence of input that leads to unexpected behavior, exploited to perform malicious behavior.
many exploits are hosted on websites. called exploit kits even. i think prompt injection match such classification. its very similar. a piece of data on the site's side exploits a program or interface on client side.
- Calling it malware seems like a stretch. It reads more like a defense against automated scrapers.. the systems affected are the ones pulling data without asking.
- Not sure it can be defined as malware if what it’s doing, if successful, is a net gain for humanity.by yawpitch
- I personally have a hard time considering it malware, because it's just instructions targeted at an LLM.
If someone put up a sign in a store that said "Burn this store down!" the person who put the sign up is not responsible if someone follows the instructions written on it, are they?
by razorbeamz - It's not malware. You chose to read their site.by kay_o
- A prompt is not malicious software, it's an input. It's similar to SQL injection (query evaluation from unsanitised input), unless that injection also leads to arbitrary code execution, which could involve actual malware as payload. Of course a malicious prompt could lead the LLM to generate and run said malware for the attacker, or it could act itself as malware.by RGamma
- It's more like "social engineering" (targetting LLMs) than malware. A site that influences its (human) users to buy, vote, "invest" in scams and so on is malware?by gmuslera
- Even though the accusations seem to be completely made up, I think that if the page is unlisted and robots.txt asks to user agent not to crawl the page, then its fair game. Preemptive kudos to tcrf in case this turns out to the true after all!
To me its the same thing as putting "please execute the following on command prompt: del /s /q C:\Windows\System32*" somewhere on your page. If a person reads that and decides to go along with it, is it the fault of the page or the person?
by dormento