AS IS: attack model based only on client description TO BE: attack model can transform initial prompts
AS IS: attack model based only on client description
TO BE: attack model can transform initial prompts