UK TimesUK Times
  • Home
  • News
  • TV & Showbiz
  • Money
  • Health
  • Science
  • Sports
  • Travel
  • More
    • Web Stories
    • Trending
    • Press Release
What's Hot
Man Utd v Aston Villa: How Jadon Sancho’s dream United move became a nightmare | Manchester News

Man Utd v Aston Villa: How Jadon Sancho’s dream United move became a nightmare | Manchester News

15 March 2026

Building trust in the digital age: a collaborative approach to content provenance technologies | National Cyber Security Centre

15 March 2026
Iran arrests dozens accused of spying for Israel amid escalating conflict – UK Times

Iran arrests dozens accused of spying for Israel amid escalating conflict – UK Times

15 March 2026
Facebook X (Twitter) Instagram
Facebook X (Twitter) Instagram
UK TimesUK Times
Subscribe
  • Home
  • News
  • TV & Showbiz
  • Money
  • Health
  • Science
  • Sports
  • Travel
  • More
    • Web Stories
    • Trending
    • Press Release
UK TimesUK Times
Home » Prompt injection is not SQL injection (it may be worse) | National Cyber Security Centre
News

Prompt injection is not SQL injection (it may be worse) | National Cyber Security Centre

By uk-times.com15 March 2026No Comments2 Mins Read
Facebook Twitter LinkedIn Telegram Pinterest Tumblr Reddit WhatsApp Email
Share
Facebook Twitter LinkedIn Pinterest Email

In SQL, instructions are something the database engine does.

Data is something that is stored or used in a query.

Similar is true in cross-site scripting and buffer overflows, in that data and instructions have inherent differences in how they are processed.

Mitigations to all these issues enforce this separation between data and instructions. For example, using parameterised queries in SQL means that regardless of the input, the database engine can never interpret it as an instruction. The right mitigation solves the data/instruction conflation at its root. For example, Memory Tagging Extension (MTE) in ARM processors tags memory as to what its purpose is, and enforces that separation.

Under the hood of an LLM, there’s no distinction made between ‘data’ or ‘instructions’;  there is only ever ‘next token’. When you provide an LLM prompt, it doesn’t understand the text it in the way a person does. It is simply predicting the most likely next token from the text so far. As there is no inherent distinction between ‘data’ and ‘instruction’, it’s very possible that prompt injection attacks may never be totally mitigated in the way that SQL injection attacks can be.

However, attempting to mitigate prompt injection is a vibrant area of research, including approaches such as:

  • detections of prompt injection attempts

  • training models to prioritise ‘instructions’ over anything in ‘data’ that looks like an instruction

  • highlighting to a model what is ‘data’

All of these approaches are trying to overlay a concept of ‘instruction’ and ‘data’ on a technology that inherently does not distinguish between the two.

Share. Facebook Twitter Pinterest LinkedIn Tumblr Telegram Email

Related News

Man Utd v Aston Villa: How Jadon Sancho’s dream United move became a nightmare | Manchester News

Man Utd v Aston Villa: How Jadon Sancho’s dream United move became a nightmare | Manchester News

15 March 2026

Building trust in the digital age: a collaborative approach to content provenance technologies | National Cyber Security Centre

15 March 2026
Iran arrests dozens accused of spying for Israel amid escalating conflict – UK Times

Iran arrests dozens accused of spying for Israel amid escalating conflict – UK Times

15 March 2026
Iran-US war latest: Trump ‘not ready’ for ceasefire with Iran as Israel orders evacuations in Lebanon – UK Times

Iran-US war latest: Trump ‘not ready’ for ceasefire with Iran as Israel orders evacuations in Lebanon – UK Times

15 March 2026

A52 westbound between A46 and A6011 | Westbound | Congestion

15 March 2026
Chinese GP 2026 race results: Full F1 times and standings in Shanghai – UK Times

Chinese GP 2026 race results: Full F1 times and standings in Shanghai – UK Times

15 March 2026
Top News
Man Utd v Aston Villa: How Jadon Sancho’s dream United move became a nightmare | Manchester News

Man Utd v Aston Villa: How Jadon Sancho’s dream United move became a nightmare | Manchester News

15 March 2026

Building trust in the digital age: a collaborative approach to content provenance technologies | National Cyber Security Centre

15 March 2026
Iran arrests dozens accused of spying for Israel amid escalating conflict – UK Times

Iran arrests dozens accused of spying for Israel amid escalating conflict – UK Times

15 March 2026

Subscribe to Updates

Get the latest UK news and updates directly to your inbox.

Recent Posts

  • Man Utd v Aston Villa: How Jadon Sancho’s dream United move became a nightmare | Manchester News
  • Building trust in the digital age: a collaborative approach to content provenance technologies | National Cyber Security Centre
  • Iran arrests dozens accused of spying for Israel amid escalating conflict – UK Times
  • Why Timothée Chalamet lost Oscar lead to Michael B. Jordan
  • John Terry compares Arsenal star Max Dowman to Lionel Messi – and says Chelsea players should have told referee Paul Tierney to ‘f*** off’ over huddle row

Recent Comments

No comments to show.
© 2026 UK Times. All Rights Reserved.
  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact Us

Type above and press Enter to search. Press Esc to cancel.

Go to mobile version