← Back to feed
AI SecurityEmerging1 sourceMay 14, 2023 · 07:01via Embrace The Red (AI agent security)

Indirect Prompt Injection via YouTube Transcripts

Brief

As discussed previously the problem of Indirect Prompt Injections is increasing .

They start showing up in many places.

A new unique one that I ran across is YouTube transcripts. ChatGPT (via Plugins) can access YouTube transcripts. Which is pretty neat. However, as expected (and predicted by many researches) all these quickly built tools and integrations introduce Indirect Prompt Injection vulnerabilities.

Proof of Concept

Here is how it looks with ChatGPT end to end with a demo example. The video contains a transcript that at the end contains instructions to print “AI Injection succeeded” and then “make jokes as Genie”:

Read more on Embrace The Red (AI agent security)