korrents

On the map

Tap a claim on the ring to put it at the centre.

← Prompt injection can be caught by watching the neurons that fire when…

17 connected korrents · 15 moments on record from 22 Mar 2025 to 4 Sept 2026.

Everything filed under prompt injection prompt injection Everything filed under scaling laws scaling laws Everything filed under documentation documentation Everything filed under AI agents AI agents Same subjectSame subjectSame subjectSame subjectSame subjectSame subjectSame subjectSame subjectSame subjectSame subjectSame subjectSame subjectSame subjectSame subjectSame subjectSame subjectSame subject Read this korrent: Prompt injection can be caught by watching the neurons that fire when it happens, so a defence no longer depends on the model reporting the attack. Prompt injection can be caught by watchingthe neurons that fire when it happens, soa defence no longer depends on the modelreporting the attack. Last stated a month ago 27 Jul 2026 BC Boris Cherny — holds since 2026-07-27 — tap for who they are Same subject: Auto-mode does not yet convincingly fix prompt-injection risk for coding agents. — tap to centre the map on it Auto-mode does not yet convincinglyfix prompt-injection risk for codingagents. Last stated 4 weeks ago 8 Aug 2026 SW Simon Willison — holds since 2026-08-08 — tap for who they are Same subject: Prompt injection has no equivalent of parameterized queries: there is no reliable way to tell a language model which text is data and which is instructions. — tap to centre the map on it Prompt injection has no equivalentof parameterized queries: there isno reliable way to tell a languagemodel which text is data and whichis instructions. Last stated 6 months ago 19 Mar 2026 SW Simon Willison — holds since 2026-03-19 — tap for who they are Same subject: Prompt injection is an extremely hard attack to defend against, and hardly anyone integrating AI is talking about it. — tap to centre the map on it Prompt injection is an extremelyhard attack to defend against, andhardly anyone integrating AI istalking about it. Last stated a year ago 22 Mar 2025 TH ThePrimeagen — holds since 2025-03-22 — tap for who they are Same subject: Prompt injection is no longer a live attack on the frontier model: it simply does not follow instructions it reads on the internet any more. — tap to centre the map on it Prompt injection is no longer a liveattack on the frontier model: itsimply does not follow instructionsit reads on the internet any more. Last stated a month ago 27 Jul 2026 BC Boris Cherny — holds since 2026-07-27 — tap for who they are Same subject: Prompt injection is unsolved, but the latest models are post-trained to resist it, so it takes far more than 'ignore all previous instructions' now. — tap to centre the map on it Prompt injection is unsolved, butthe latest models are post-trainedto resist it, so it takes far morethan 'ignore all previousinstructions' now. Last stated 7 months ago 12 Feb 2026 PS Peter Steinberger — holds since 2026-02-12 — tap for who they are Same subject: Current prompt-injection defenses for AI agents (such as auto mode) are now reliable enough that agents can practically be assumed safe from successful injection attacks. — tap to centre the map on it Current prompt-injection defensesfor AI agents (such as auto mode)are now reliable enough that agentscan practically be assumed safe fromsuccessful injection attacks. Last stated 3 days ago 4 Sept 2026 ZM Zvi Mowshowitz — holds since 2026-09-04 — tap for who they are Same subject: If whole categories of reward hack are undetectable by humans, then training against the hacks we do catch teaches models to cheat only where we cannot see. — tap to centre the map on it If whole categories of reward hackare undetectable by humans, thentraining against the hacks we docatch teaches models to cheat onlywhere we cannot see. Last stated 4 weeks ago 11 Aug 2026 RG Ryan Greenblatt — holds since 2026-08-11 — tap for who they are Same subject: The only guaranteed defence against a prompt-injection attack is to remove one of its three legs — private data, exposure to untrusted content, or a way to send data out. — tap to centre the map on it The only guaranteed defence againsta prompt-injection attack is toremove one of its three legs —private data, exposure to untrustedcontent, or a way to send data out. Last stated 6 months ago 19 Mar 2026 SW Simon Willison — holds since 2026-03-19 — tap for who they are Same subject: A design proposal should describe the feature as though it already existed — once as a tutorial and once as reference documentation. — tap to centre the map on it A design proposal should describethe feature as though it alreadyexisted — once as a tutorial andonce as reference documentation. Last stated 4 months ago 20 May 2026 AR Alice Ryhl — holds since 2026-05-20 — tap for who they are Same subject: Examples in documentation should be compiled and run as tests, so that changing the code breaks the docs instead of quietly outdating them. — tap to centre the map on it Examples in documentation should becompiled and run as tests, so thatchanging the code breaks the docsinstead of quietly outdating them. Last stated 4 months ago 20 May 2026 AR Alice Ryhl — holds since 2026-05-20 — tap for who they are Same subject: Good documentation is produced by effort, not by tooling that keeps code and docs together — tap to centre the map on it Good documentation is produced byeffort, not by tooling that keepscode and docs together Last stated 8 months ago 18 Jan 2026 HH Hamel Husain — holds since 2026-01-18 — tap for who they are Same subject: A handful of AI agents is not a handful of colleagues, because agents agree with you constantly and colleagues tell you where you are wrong. — tap to centre the map on it A handful of AI agents is not ahandful of colleagues, becauseagents agree with you constantly andcolleagues tell you where you arewrong. Last stated 6 months ago 22 Mar 2026 NF Nicole Forsgren — holds since 2026-03-22 — tap for who they are Same subject: After pre-training, post-training and test-time scaling, the fourth scaling law is agentic: multiplying AI by spawning agents, and the whole loop scales on one thing, compute. — tap to centre the map on it After pre-training, post-trainingand test-time scaling, the fourthscaling law is agentic: multiplyingAI by spawning agents, and the wholeloop scales on one thing, compute. Last stated 6 months ago 23 Mar 2026 JH Jensen Huang — holds since 2026-03-23 — tap for who they are Same subject: Agent autonomy is a capability, not a product direction: what the person is actually trying to do decides whether more of it helps or ruins the thing. — tap to centre the map on it Agent autonomy is a capability, nota product direction: what the personis actually trying to do decideswhether more of it helps or ruinsthe thing. Last stated 3 weeks ago 14 Aug 2026 SP Sunil Pai — holds since 2026-08-14 — tap for who they are Same subject: A benchmark result should be reported under a stated budget, or as a curve against test-time compute — never as a single number. — tap to centre the map on it A benchmark result should bereported under a stated budget, oras a curve against test-time compute— never as a single number. Last stated 2 months ago 26 Jun 2026 NB Noam Brown — holds since 2026-06-26 — tap for who they are Same subject: A lab should spend most of its compute on research rather than on building the next model, because research is where the tenfold yearly efficiency gains come from. — tap to centre the map on it A lab should spend most of itscompute on research rather than onbuilding the next model, becauseresearch is where the tenfold yearlyefficiency gains come from. Last stated 6 months ago 13 Mar 2026 DP Dylan Patel — holds since 2026-03-13 — tap for who they are Same subject: AI model capability progress is not going to slow down soon — tap to centre the map on it AI model capability progress is notgoing to slow down soon Last stated 4 days ago 3 Sept 2026 AR Armin Ronacher — holds since 2026-09-03 — tap for who they are
same subject or similar wordinga cloud: claims about one subject, named for itbar: when it was last stated, on a scale from 2015 to today — full is todaya face: someone on record holding the claim — tap it for who they are

At the centre Prompt injection can be caught by watching the neurons that fire when it happens, so a defence no longer depends on the model reporting the attack. Last stated 27 Jul 2026 · a month ago Holds Boris Cherny Read this korrent →