simonw 2 days ago

Text in the image and text in the prompt can both be used by attackers to subvert the model's original instructions.