|
|
|
|
|
by andy99
32 days ago
|
|
How compatible is never replying with the threat model you are trying to avoid? Attack success is probably more likely when the attacker can iterate based on replies or engage in multi-turn conversations. Here they’re just taking stabs in the dark with no feedback. Does that accurately represent the access a real attacker might have? |
|
Having the agent reply would have been more fun and a better excercise, but too expensive.