Delimiters and Special Character Extraction

Type: technique

Description: The adversary extracts delimiters and special characters set for the LLM, such as those used in RAG applications to differentiate between context and user prompts. These can later be exploited to confuse or manipulate the LLM into misbehaving.

Version: 0.1.0

Created At: 2024-10-03 22:24:49 +0300

Last Modified At: 2024-10-03 22:24:49 +0300


External References

  • --> Discovery (tactic): An adversary can discover information about how the AI system distinguishes between context and user prompts or retrieve special characters used by the system to facilitate future attacks