UK TimesUK Times
  • Home
  • News
  • TV & Showbiz
  • Money
  • Health
  • Science
  • Sports
  • Travel
  • More
    • Web Stories
    • Trending
    • Press Release
What's Hot
Pundits criticise bizarre Chelsea huddle as players surround referee: ‘A farce’ – UK Times

Pundits criticise bizarre Chelsea huddle as players surround referee: ‘A farce’ – UK Times

15 March 2026

How GOV.UK Pay grew to processing £8 billion in transactions – Government Digital Service

15 March 2026
OFFICIAL: Formula One CANCELS races in the Middle East amidst ongoing conflict

OFFICIAL: Formula One CANCELS races in the Middle East amidst ongoing conflict

15 March 2026
Facebook X (Twitter) Instagram
Facebook X (Twitter) Instagram
UK TimesUK Times
Subscribe
  • Home
  • News
  • TV & Showbiz
  • Money
  • Health
  • Science
  • Sports
  • Travel
  • More
    • Web Stories
    • Trending
    • Press Release
UK TimesUK Times
Home » Prompt injection is not SQL injection (it may be worse) | National Cyber Security Centre
News

Prompt injection is not SQL injection (it may be worse) | National Cyber Security Centre

By uk-times.com15 March 2026No Comments2 Mins Read
Facebook Twitter LinkedIn Telegram Pinterest Tumblr Reddit WhatsApp Email
Share
Facebook Twitter LinkedIn Pinterest Email

In SQL, instructions are something the database engine does.

Data is something that is stored or used in a query.

Similar is true in cross-site scripting and buffer overflows, in that data and instructions have inherent differences in how they are processed.

Mitigations to all these issues enforce this separation between data and instructions. For example, using parameterised queries in SQL means that regardless of the input, the database engine can never interpret it as an instruction. The right mitigation solves the data/instruction conflation at its root. For example, Memory Tagging Extension (MTE) in ARM processors tags memory as to what its purpose is, and enforces that separation.

Under the hood of an LLM, there’s no distinction made between ‘data’ or ‘instructions’;  there is only ever ‘next token’. When you provide an LLM prompt, it doesn’t understand the text it in the way a person does. It is simply predicting the most likely next token from the text so far. As there is no inherent distinction between ‘data’ and ‘instruction’, it’s very possible that prompt injection attacks may never be totally mitigated in the way that SQL injection attacks can be.

However, attempting to mitigate prompt injection is a vibrant area of research, including approaches such as:

  • detections of prompt injection attempts

  • training models to prioritise ‘instructions’ over anything in ‘data’ that looks like an instruction

  • highlighting to a model what is ‘data’

All of these approaches are trying to overlay a concept of ‘instruction’ and ‘data’ on a technology that inherently does not distinguish between the two.

Share. Facebook Twitter Pinterest LinkedIn Tumblr Telegram Email

Related News

Pundits criticise bizarre Chelsea huddle as players surround referee: ‘A farce’ – UK Times

Pundits criticise bizarre Chelsea huddle as players surround referee: ‘A farce’ – UK Times

15 March 2026

How GOV.UK Pay grew to processing £8 billion in transactions – Government Digital Service

15 March 2026
Junior Andre shares first look at major career move | Lifestyle – UK Times

Junior Andre shares first look at major career move | Lifestyle – UK Times

15 March 2026

Local Government Reorganisation (LGR) full proposal to Government

15 March 2026
As other Iran‑allied groups are engaging in the Mideast war, Yemen’s Houthis hold back – UK Times

As other Iran‑allied groups are engaging in the Mideast war, Yemen’s Houthis hold back – UK Times

15 March 2026

Workshop resolves to boost Marches business resilience and green growth

15 March 2026
Top News
Pundits criticise bizarre Chelsea huddle as players surround referee: ‘A farce’ – UK Times

Pundits criticise bizarre Chelsea huddle as players surround referee: ‘A farce’ – UK Times

15 March 2026

How GOV.UK Pay grew to processing £8 billion in transactions – Government Digital Service

15 March 2026
OFFICIAL: Formula One CANCELS races in the Middle East amidst ongoing conflict

OFFICIAL: Formula One CANCELS races in the Middle East amidst ongoing conflict

15 March 2026

Subscribe to Updates

Get the latest UK news and updates directly to your inbox.

Recent Posts

  • Pundits criticise bizarre Chelsea huddle as players surround referee: ‘A farce’ – UK Times
  • How GOV.UK Pay grew to processing £8 billion in transactions – Government Digital Service
  • OFFICIAL: Formula One CANCELS races in the Middle East amidst ongoing conflict
  • Junior Andre shares first look at major career move | Lifestyle – UK Times
  • Local Government Reorganisation (LGR) full proposal to Government

Recent Comments

No comments to show.
© 2026 UK Times. All Rights Reserved.
  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact Us

Type above and press Enter to search. Press Esc to cancel.

Go to mobile version