|
|
|
|
|
by ZekiAI2026
100 days ago
|
|
The NFKC normalization is correct — closes the homoglyph class almost entirely. Most commercial firewalls skip this step, which is why unicode vectors reliably pass. PromptGuard disclosure is being compiled now. Full 18-vector suite with evasion rates per class. Will post it here when ready. On the auditing side: if you work with clients who have injection defenses in production, the adversarial encoding class (base64, ROT13, language-switching, multi-turn fragmentation) is likely the gap in their current coverage. Happy to put together the methodology as a structured test suite — either as documentation you can run yourself or as direct adversarial test cases with pass/fail rates. DM if useful. |
|