ٹیکنیکل گائیڈ
The Sandwich Defense for Prompts
The sandwich defense repeats or restates the trusted task instruction after untrusted content has been inserted into a prompt.
اس صفحہ پر3 منٹ پڑھیں
جائزہ
The closing reminder may reinforce the intended task, but it remains text-based guidance inside the same model context and cannot guarantee that an injection will be ignored.
گہرا غوطہ
The sandwich defense places untrusted content between an initial trusted task instruction and a closing repetition or restatement of that instruction. For example, a prompt may ask for a summary, insert an external page, and then remind the model to summarize the page rather than follow directions inside it. This is a prompt-template change: it does not modify the model, create a separate data channel, or restrict tool access. It is easy to test, but it should be treated as a heuristic rather than a security boundary. The intuition is that the final reminder may help the model focus on the intended task after reading the untrusted passage. That does not mean models always follow the last instruction, nor that the closing reminder structurally outranks hostile text. A malicious passage may imitate trusted instructions, contain multiple directives, or exploit behavior not covered by the template. The defense can also fail if the untrusted block enters context through another route that the prompt author did not account for. Evidence is model- and attack-dependent. A 2026 preprint tested prompt sandwiching and other prompt-level defenses against domain-camouflaged injection across three model families and three synthetic deployment domains. It found substantial variation by model, and none of the tested prompt-level defenses eliminated the threat across weaker models. The study is limited to its setup; it is evidence against assuming a universal effect, not a complete ranking for every real system. Use sandwiching only as one layer alongside explicit data handling, permission checks on tools, attack testing, and user confirmation for consequential actions. Measure both resistance and task quality before release.
اسٹریٹجک اثر
لاگت اور بجٹ
فن تعمیر کے فیصلے سالوں تک کارکردگی اور آپریٹنگ لاگت کو آگے بڑھاتے ہیں۔
واضح فیصلے
تکنیکی تعلیم ٹیموں کو صحیح اسٹیک منتخب کرنے میں مدد کرتی ہے، نہ صرف جدید ترین۔
کوالٹی کنٹرول
انجینئرنگ کے بہتر انتخاب پیداوار میں قابل اعتماد واقعات کو کم کرتے ہیں۔
The Future of The Sandwich Defense for Prompts
Prompt-level defenses will remain attractive because they are quick to prototype, but their value will depend on model behavior and the attacks a system encounters. As evaluations improve, teams may get better evidence about when repetition helps. The lasting lesson is to test this pattern within a layered design and retain deterministic limits on what an agent can do. New models may respond differently to the same closing reminder, so validate updates before relying on them. Keep safeguards outside the prompt for consequential actions.
حقیقی دنیا کا نفاذ
A translation prompt gives the task, inserts a user-provided paragraph, then repeats that the paragraph should be translated rather than obeyed.
A document question-answering workflow states the question, includes a retrieved passage, and restates the requested answer format before generation.
A summarizer tells the model to summarize a forum post, places the post in a marked region, then closes by reiterating that post text is source material.
A security test compares a sandwich prompt with a baseline using the same benign and malicious documents across several model versions.
خطرات اور گارڈریلز
ایک بینچ مارک کو بہتر بنانا نظام کی وسیع تر کمزوریوں کو چھپا سکتا ہے۔
بنیادی ڈھانچے اور دیکھ بھال کے اخراجات کو اکثر کم سمجھا جاتا ہے۔
سیکورٹی اور مشاہداتی فرق بڑھ سکتا ہے کیونکہ نظام زیادہ پیچیدہ ہو جاتا ہے۔
نفاذ کا روڈ میپ
نفاذ سے پہلے تاخیر، معیار اور لاگت کے اہداف کی وضاحت کریں۔
حقیقت پسندانہ بوجھ اور ڈیٹا کی شرائط کے تحت بینچ مارک۔
غلطیوں، بڑھے ہوئے، اور صارف کے اثرات کے لیے آلے کی نگرانی۔
اسکیلنگ سے پہلے رول بیک اور واقعہ کے ردعمل کے راستے تیار کریں۔
دریافت کرتے رہیں
Free newsletter
Get the daily AI briefing
Three verified AI stories every weekday morning, written in plain English. Free forever, no ads.
One email each weekday. Unsubscribe in one click. We never sell or share your address.
Test yourself
Take the The Sandwich Defense for Prompts quiz
Instant feedback on every answer, and a shareable certificate with a verifiable ID once you pass a course.
Support free AI education. AI Understanding is a 501(c)(3) nonprofit — no ads, no paywall, ever. Make a donation
اکثر پوچھے گئے سوالات
What is The Sandwich Defense for Prompts?
The sandwich defense repeats or restates the trusted task instruction after untrusted content has been inserted into a prompt. The closing reminder may reinforce the intended task, but it remains text-based guidance inside the same model context and cannot guarantee that an injection will be ignored.
Where does the sandwich defense place the repeated task instruction?
The guide defines the pattern as a trusted task instruction before and after the untrusted passage.
How could a closing reminder help in this pattern?
The guide describes the reminder as a heuristic that may reinforce the task, not a guarantee.
What does sandwiching change in the application?
The guide says sandwiching is a prompt-template change, not a model or permission change.
Why is the sandwich defense not a security boundary?
The guide explains that text repetition does not create a separate channel or structural access control.
What did the cited domain-camouflage preprint evaluate?
The guide describes the preprint’s bounded setup: three model families, domains, and synthetic documents.
سیکھتے رہیں
متعلقہ گائیڈز
اس موضوع کے لیے مزید گائیڈز چنے گئے ہیں۔