s
April 16, 2024, 9:28 p.m. |

Simon Willison's Weblog simonwillison.net

Google NotebookLM Data Exfiltration


NotebookLM is a Google Labs product that lets you store information as sources (mainly text files in PDF) and then ask questions against those sources - effectively an interface for building your own custom RAG (Retrieval Augmented Generation) chatbots.


Unsurprisingly for anything that allows LLMs to interact with untrusted documents, it's susceptible to prompt injection.


Johann Rehberger found some classic prompt injection exfiltration attacks: you can create source documents with instructions that cause the chatbot to …

ai building chatbots data documents files generativeai google google notebooklm information labs llms notebooklm pdf product promptinjection questions rag retrieval retrieval augmented generation security store text

Data Engineer

@ Lemon.io | Remote: Europe, LATAM, Canada, UK, Asia, Oceania

Artificial Intelligence – Bioinformatic Expert

@ University of Texas Medical Branch | Galveston, TX

Lead Developer (AI)

@ Cere Network | San Francisco, US

Research Engineer

@ Allora Labs | Remote

Ecosystem Manager

@ Allora Labs | Remote

Founding AI Engineer, Agents

@ Occam AI | New York