Equation 3 · The Attack Surface That Reads
What does this equation mean?
Read the formula alongside the article passage below. Each part has a deeper page with its role in the equation, the supporting passage and nearby citations.
This equation states an equality: the expressions on both sides have the same value under the article’s assumptions. Read the equation part by part below; each part has a contextual explanation and a link to its mathematical background.
Read it piece by piece
Symbol P_bypass
ypass is part of the quantity the equation computes from the expression on the right.
Symbol i
i appears in the bound of this product. The bound states where the repeated operation starts, ends, or which values it includes.
Symbol n
n appears in the bound of this product. The bound states where the repeated operation starts, ends, or which values it includes.
=
The expressions on both sides represent the same quantity under the stated assumptions.
See an illustrated explanation →subscript
The lower label selects a particular version, component, or indexed member of the quantity. For example, x₀ and xₜ can be values at different positions.
superscript
A raised number can be a power. When it is a label or bound, it selects a case or the upper limit of a sum; the formula’s structure distinguishes these uses.
See an illustrated explanation →Starting index or lower bound: i=1
This label says where the repeated addition, multiplication, or accumulation starts. Read its value or condition together with the article’s description of the index.
Ending index or upper bound: n
This label says where the repeated addition, multiplication, or accumulation stops. It sets the last term or end of the range.
How to interpret it
Read it with the definitions, units, and assumptions supplied by the article.
What the article says around this equation
Here is the modelling error to avoid. Suppose a request passes n independent detection layers, each of which fails to catch a given malicious input with probability . It is tempting to write the bypass probability of the stack as . and conclude that four layers at ten percent leakage each give one bypass in ten thousand. That number is an artefact of the independence assumption, and the assumption is the weakest part of the model. The layers are typically built from the same model family, trained on overlapping data, and sensitive to the same features of an input; their failures are positively correlated, so the true joint failure probability is larger than the…
Read the full surrounding passage
Here is the modelling error to avoid. Suppose a request passes n independent detection layers, each of which fails to catch a given malicious input with probability . It is tempting to write the bypass probability of the stack as . and conclude that four layers at ten percent leakage each give one bypass in ten thousand. That number is an artefact of the independence assumption, and the assumption is the weakest part of the model. The layers are typically built from the same model family, trained on overlapping data, and sensitive to the same features of an input; their failures are positively correlated, so the true joint failure probability is larger than the product. Worse, an adaptive adversary is not sampling inputs at random. They are searching for an input in the region where the layers fail together — which is exactly the correlated tail the product form assumes away. The honest quantity is the joint probability under an adversarially chosen input distribution, and no one currently knows how to measure it in a way that transfers to a new attack.
Sources cited in the article section
- [10] The Instruction Hierarchy: Training LLMs to Prioritize Privileged Instructions ↗
- [11] Lessons from Defending Gemini Against Indirect Prompt Injections ↗
- [12] Mitigating prompt injection attacks with a layered defense strategy ↗
These citations give research context. Read each source to check which claims it supports.
Return to The Attack Surface That Reads