张杰谈VLM提示注入防御思路
AI 导读
当 @JieZhang_ETH 提出这个项目时,我开玩笑说我知道这想法来自他而不是 LLM,因为它太古怪了。 我这是赞美! 当我们被 AI 垃圾研究淹没时,偏离常规、尝试古怪的东西比以往任何时候都更重要。
正文
When @JieZhang_ETH pitched this project, I joked that I knew the idea was from him and not an LLM as it was too weird.
I meant this as a compliment!
As we get inundated with AI slop research, it's more important than ever to wander off the beaten path and try weird things
1/ We know VLMs mostly learn instruction-following from text, so for them an image is something to describe, not obey. Can we turn that into a prompt injection defense? 🧵在 X 查看被引用的帖子