Hacker News new | ask | show | jobs
by aix1 113 days ago
Yeah, how exactly would that work?
1 comments

A schema with response metadata (so responses that deviate from it fail automatically), plus a challenge question that's calibrated to be hard enough that the disruption of instruction following from prompt injection can cause the model to answer incorrectly.