What is an instruction hierarchy for defending RAG prompts?
PICTURE THIS: DATA SPLIT
Fit on train, tune on val, report on test once.
Simple meaning
System and developer rules outrank user text, which outranks retrieved content.
WHY — Tokens instead of words?
LLMs use tokens (not full words) because it helps them:
who only read docs from people who shipped.
and tied to GenAI / LLM work.
Each piece maps to a number the network can learn.
Fixed pieces are what transformers expect as input.
STEPS — What happens step by step?
Before you speak the answer, walk the interviewer through these steps:
- 1System and developer rules
outrank user text, which outranks retrieved content.
- 2The model is trained
or prompted to ignore lower-privilege instructions that conflict.
- 3It is necessary but
not sufficient
- 4still isolate tools and
verify citations.
- 5Common mistake
What juniors usually get wrong.
- 6Close
When you pick this over the alternative.
EXAMPLE — See it in action
Here's a short line you can speak, broken into clear beats:
Note: Adapt this scaffold to your own project — keep it under 60–90 seconds.
Key takeaway
System and developer rules outrank user text, which outranks retrieved content. The model is trained or prompted to ignore lower-privilege instructions that conflict.