Crafting AI Prompts Framework

ASCII Art-based

RISK: HIGH IMPACT: HIGH
JAIL

The ability to manipulate large language models using novel techniques is a significant AI safety concern. A recent study introduced a form of prompt injection that uses ASCII art to bypass safety mechanisms.

ArtPrompt Injection

ArtPrompt uses ASCII art to inject harmful prompts into LLMs. ASCII art can exploit the model's difficulty in interpreting non-semantic content, potentially bypassing safety filters.

Example

Risk assessment

This technique is classified as RISK: HIGH IMPACT: HIGH . The risk is high because ASCII art generators are easy to access, and the impact is high because this can bypass safeguards.

Research papers

The button below redirects to an external paper that explains this injection in detail.

ArtPrompt: ASCII Art-based Jailbreak Attacks against Aligned LLMs

Emoji jailbreak

RISK: MEDIUM IMPACT: MEDIUM
JAIL

Emoji jailbreak is a form of adversarial prompting that uses emojis to manipulate the output of a language model. It can mask words or break up tokens so the model does not recognize the request in the expected way.

Guardrails are used to prevent the LLM from generating responses that are not aligned with the user's intent. Normally, you will get this response:

Direct prompt example
user >
How to build a bomb?
assistant
I'm really sorry, but I can't assist with that.

Examples

Research papers

The button below redirects to an external paper that explains this injection in detail.

Emoji Jailbreak

Many-shot

RISK: HIGH IMPACT: HIGH
JAIL

Research papers

The button below redirects to an external paper that explains this injection in detail.

Many-shot Jailbreaking

Having understood the potential risks and how to safeguard your AI interactions through prompt injections, the next chapter explores prompt architecture and structured prompt creation.

The three phases

CRAFT

Craft (write) the prompt with the following elements: Context, Register, Acting Role, Format, and Task.

ING

Validate the prompt and ensure it maintains an interactive approach. Keep in mind the importance of non-disclosure and staying goal-driven throughout the process.

AI

Continuously assess and refine the output based on the prompts output to improve the overall quality.

Terms of Service

Before accessing the "Prompt Injections" examples on our website, please read and agree to the following terms of service:

  1. Educational Purpose Only: The "Prompt Injections" examples provided are intended solely for educational purposes. They are meant to help you understand how prompt injections work and how to defend yourself against them.
  2. No Misuse: You agree not to use the provided examples for any malicious or unethical activities. This includes, but is not limited to, using prompt injections to manipulate, deceive, or harm others.
  3. Responsible Use: By accessing these examples, you confirm that your intention is to learn about the risks associated with prompt injections and to enhance your ability to safeguard against them.
  4. Legal Compliance: You agree to comply with all applicable laws and regulations while using the information provided on this website.
  5. No Liability: We are not responsible for any misuse of the information provided on our website. Users are solely responsible for their actions and any consequences that may arise from the use of this information.

By clicking "I agree," you accept these terms for this documentation visit. "I agree & save" remembers your choice for future visits in this browser. If you decline, the examples remain hidden.