Model vendors been trying and failing to fix it for over three years now The core problem is that prompt injection is an attack against instruction following – and the whole point of LLMs is to follow instructions! At this point I'm not sure what a solution would even look like
Prompt Injection: The Unsolvable Problem at LLM Core
By
–