s
April 14, 2023, 6:33 p.m. |

Simon Willison's Weblog simonwillison.net

New prompt injection attack on ChatGPT web version. Markdown images can steal your chat data


An ingenious new prompt injection / data exfiltration vector from Roman Samoilenko, based on the observation that ChatGPT can render markdown images in a way that can exfiltrate data to the image hosting server by embedding it in the image URL. Roman uses a single pixel image for that, and combines it with a trick where copy events on a website are intercepted and prompt …

ai chat chatgpt data embedding events generativeai image images llms markdown observation pixel prompt promptengineering prompt injection promptinjection security server vector web website

Data Architect

@ University of Texas at Austin | Austin, TX

Data ETL Engineer

@ University of Texas at Austin | Austin, TX

Lead GNSS Data Scientist

@ Lurra Systems | Melbourne

Senior Machine Learning Engineer (MLOps)

@ Promaton | Remote, Europe

Software Engineer, Data Tools - Full Stack

@ DoorDash | Pune, India

Senior Data Analyst

@ Artsy | New York City