<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Prompt-Injection on Ashwin Viswamithiran</title><link>https://ashwinviswamithiran.com/tags/prompt-injection/</link><description>Recent content in Prompt-Injection on Ashwin Viswamithiran</description><image><title>Ashwin Viswamithiran</title><url>https://ashwinviswamithiran.com/og-default.png</url><link>https://ashwinviswamithiran.com/og-default.png</link></image><generator>Hugo</generator><language>en-us</language><lastBuildDate>Tue, 29 Sep 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://ashwinviswamithiran.com/tags/prompt-injection/index.xml" rel="self" type="application/rss+xml"/><item><title>Every Attack Here Is a Prompt Injection</title><link>https://ashwinviswamithiran.com/writing/attacks-that-worked/</link><pubDate>Mon, 28 Sep 2026 00:00:00 +0000</pubDate><guid>https://ashwinviswamithiran.com/writing/attacks-that-worked/</guid><description>A technique survey of 18,479 successful prompt attacks where the correct MITRE ATLAS label is known in advance from how the competition was scored. Keyword attribution recovers 11.4% of it, and most of the remaining breakdown describes the challenges rather than the attackers.</description></item><item><title>Sizing a Fingerprint for Prompt Attacks</title><link>https://ashwinviswamithiran.com/writing/promptlsh-evaluation/</link><pubDate>Tue, 08 Sep 2026 00:00:00 +0000</pubDate><guid>https://ashwinviswamithiran.com/writing/promptlsh-evaluation/</guid><description>Two organisations cannot compare prompt attacks by sharing the prompts: those are things users wrote. A compact derived fingerprint solves that, and this measures what each size actually buys — full float, 384-byte quantised, 32-byte digest, dependency-free lexical — on recall, on evasion resistance, and on what survives across independently collected feeds.</description></item><item><title>We've Seen This Movie Before</title><link>https://ashwinviswamithiran.com/writing/weve-seen-this-movie-before/</link><pubDate>Mon, 24 Aug 2026 00:00:00 +0000</pubDate><guid>https://ashwinviswamithiran.com/writing/weve-seen-this-movie-before/</guid><description>Prompt attacks are new. The tooling being built around them is not. It&amp;#39;s the same ladder malware defence climbed over twenty-five years, being climbed again in a handful.</description></item></channel></rss>