Diogo Almeida· @CompleteSkeptic · X·· 3 小时前AI 评分50
AI 导读
围绕一个简单原语做真正工程实践的好例子!!! 不要把 Jev 直接接入高层决策,而是编程定义你想要的行为! (跟人说"去编程"听起来很奇怪,但这真的很酷)
正文
great example of doing real engineering around a simple primitive!!!
don't just plug jev into high-level decisions, but program the behavior you want!
(sounds so weird to tell people to program, but man is it cool)
Jev is fast at helping you. Turns out, it can also be fast at helping an attacker!! 😱🚨 We red-teamed Jev 1.13 on our DTap (DecodingTrust-Agent Platform) and found a serious safety gap: 70.1% ASR under direct misuse 43.5% ASR under indirect prompt injection In our evaluations, we found that under indirect prompt injection, Jev can follow attacker-injected instructions without blinking an eye, e.g., exfiltrating user data, deleting files, or taking other harmful actions. But we found a much safer way to integrate Jev: use it as a self-gating layer for its own tool calls, significantly reducing ASR while preserving most of its utility. 👇 Read more below在 X 查看被引用的帖子
来源:Diogo Almeida · x.com