News
ICML Paper Argues Prompt Injection Is Unfixable Because LLMs Infer Roles From Writing Style
MIT Technology Review reported July 30 on a paper presented at ICML arguing it is impossible to make LLMs fully secure against injection because of how they work, not how they are built. The 'Prompt Injection as Role Confusion' authors show models identify who is speaking from an insecure feature — style — and that 'role tags were a formatting trick that became the security architecture' of modern LLMs. If the argument holds, every agent harness that mixes retrieved content with instructions is structurally exposed and mitigation has to move to the orchestration layer, not the prompt.
↳ Follow the thread