5 min read
Research Researchers demonstrated that attackers can backdoor LLMs by modifying bundled Jinja2 chat templates rather than model weights, achieving 80%+ agent hijack rates with bypasses that evade standard prompt injection defenses.
Researchers demonstrated that attackers can backdoor LLMs by modifying bundled Jinja2 chat templates rather than model weights, achieving 80%+ agent hijack rates with bypasses that evade standard prompt injection defenses.