Prompt Processing Units for Direct Prompt Injection Mitigation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing technologies lack the ability to effectively interpret and apply security controls on prompts sent to large language models (LLMs), making them vulnerable to direct prompt injection attacks, which manipulate or expose sensitive information.
Innovation Solution
Implementing prompt processing units (PPUs) to characterize and distill key features from prompts, enabling enterprises to detect and prevent mutually opposed subjects within the prompts, thereby mitigating direct prompt injection threats.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If enterprises use large language models for productivity enhancement, then productivity is improved, but vulnerability to prompt injection attacks increases
Solution Approach 1:
The patent introduces a prompt processing unit as an intermediary component between the user prompt and the large language model. This PPU analyzes prompts for mutually opposed subjects and prevents injection attacks while allowing legitimate queries to pass through, thus resolving the contradiction between enabling productivity-enhancing LLM usage and preventing security vulnerabilities
Solution Approach 2:
The system performs preliminary analysis of prompts before they are sent to the LLM by identifying mutually opposed subjects in advance. This preliminary detection and prevention mechanism allows the system to maintain both productivity benefits and security against prompt injection attacks
2Adaptability or versatility
If current LLMs interpret and execute prompts autonomously, then task completion capability is improved, but controllability and security oversight deteriorate
Solution Approach 1:
The prompt processing unit serves as a mediator that sits between the autonomous LLM execution and human security oversight. It maintains the autonomous execution capability while introducing a controllable security layer that can intervene when mutually opposed subjects are detected
Solution Approach 2:
The system segments the prompt processing function into two independent parts: the LLM's autonomous interpretation and execution capability, and the security control layer that identifies mutually opposed subjects. This segmentation allows both high adaptability and maintainable security oversight to coexist
Data Source
AI summary
In one implementation, a device identifies a first subject indicated by a prompt to a large language model. The device identifies a second subject indicated by the prompt to the large language model. The device determines whether the first subject and the second subject are mutually opposed subjects. The device prevents the large language model from processing the prompt when the first subject and the second subject are mutually opposed subjects.


