Flavio Villanustre, CISO for the LexisNexis Threat Options Group, noticed that the identical downside with combined information and directions occurred in databases many years in the past, and changed into what we all know as SQL injection assaults at this time. However, he famous, a number of years later, parametrized binding for the database entry layers was developed, which separates directions, that are dealt with internally and safely, from information, which may come from untrusted sources. “The identical must occur with LLMs and different AI,” he stated.
Mike Leone, a VP/principal analyst at Moor Insights & Technique, agreed.
“It’s onerous to not chuckle a bit with this one. Folks have been asking whether or not information may give orders since SQL injections. We fastened that one by giving the database a option to inform an instruction from a worth,” Leone stated. “Thirty years later, we’ve constructed a complete class of software program that may’t inform the distinction in any respect.”


