logoalt Hacker News

x312yesterday at 3:16 PM1 replyview on HN

The provider decrypts it and puts the decrypted reasoning into the model's context window. They prompt the model to repeat back the reasoning. So then the model echoes it back in plain text.


Replies

dborehamyesterday at 4:12 PM

Hmm, ok. So the attack doesn't involve decrypting the payload, only getting the server to do so. Since a model will do that if you just ask, what's so special about the attack?

show 1 reply