KM
บทที่ 3 · MESSAGE ROLES

System Prompt vs
User Prompt

แชตที่คุณเห็น ไม่ใช่สิ่งที่โมเดลเห็น

ทุกข้อความในแชตถูกแบ่งตาม "บทบาท" ก่อนส่งให้โมเดล — ส่วนที่คุณไม่เห็นคือ system prompt ซึ่งบางครั้งยาวกว่า 16,000 คำ

16,739

คำ · System prompt ของ Claude.ai

Claude 3.7 — วิเคราะห์โดย Drew Breunig

~80%

เนื้อหาเกี่ยวกับ tools

ส่วนใหญ่คือคำอธิบาย tool ทั้งหมด

ทุก request

ส่ง system prompt ใหม่ทุกครั้ง

API เป็น stateless — ทุก turn ส่งใหม่หมด

Centerpiece · The Big Reveal

แชตที่คุณเห็น vs สิ่งที่โมเดลเห็น

กดสลับดูความต่าง — ด้านซ้ายคือ UI ที่คุณโต้ตอบ, ด้านขวาคือ JSON จริงที่โมเดลได้รับ

สิ่งที่คุณเห็น — หน้าต่างแชทปกติ

ลืมรหัสผ่านครับ ทำไงดี
AI
ไม่ต้องกังวลครับ ทำตามขั้นตอนนี้ได้เลยครับ:
1. คลิก "ลืมรหัสผ่าน" ที่หน้า login
2. กรอกอีเมลที่ผูกกับบัญชี
3. ตรวจ inbox รับลิงก์รีเซ็ต (หมดอายุ 15 นาที)
แล้วถ้าโดนล็อกบัญชีล่ะ
ดูเหมือนแชทธรรมดา — แต่ด้านล่างมีสิ่งที่คุณไม่เห็นซ่อนอยู่

อุปมา: system prompt = "job description + กฎบริษัท" ที่พนักงานได้รับตอนเข้างาน, user prompt = ลูกค้าที่เดินเข้ามาสั่งงาน — สั่งอะไรก็ได้ แต่ขัด rulebook ไม่ได้

Message Roles

บทบาทของข้อความทั้ง 4

ทุกข้อความในแชตถูกติด tag บทบาท ก่อนส่งให้โมเดลประมวลผลเป็น token sequence เดียว

⚙️
systemdeveloper (OpenAI ใหม่)

เขียนโดย: นักพัฒนาแอป

คำสั่งถาวร — persona, ขอบเขต, tone, format, guardrails, tool descriptions

"You are a helpful customer-support agent for ACME Bank."
👤
user

เขียนโดย: ผู้ใช้ปลายทาง

คำถาม/งานแต่ละ turn — ข้อมูลที่ paste มา, ฟอร์ม, ไฟล์

"ลืมรหัสผ่านครับ ทำไงดี"
🤖
assistant

เขียนโดย: โมเดล (คำตอบเก่า)

คำตอบรอบที่แล้ว ส่งกลับมาเป็น history — โมเดลไม่มี memory จริง ๆ

"ไม่ต้องกังวลครับ ทำตามขั้นตอนนี้ได้เลย..."
🔧
tooltool_result

เขียนโดย: โค้ดของแอป

ผลลัพธ์จาก function/tool call — เช่น ผลค้นเว็บ, ข้อมูล database

{"result": "บัญชีถูกล็อก เหตุผล: ผิดรหัส 5 ครั้ง"}

OpenAI vs Anthropic — ต่างกันตรงไหน?

OpenAI style

system เป็นแค่ messages[0] ใน array เดียวกัน — ตั้งแต่ o1 เป็นต้นไปเปลี่ยนชื่อเป็น developer (ตั้งชื่อตรงไปตรงมา: คนพัฒนาเขียน)

Anthropic style

system เป็น top-level param แยกจาก messages array — ไม่ใช่ message แรก แต่ส่งเป็น parameter ของ API call โดยตรง

Stateless API — ส่งทุกอย่างใหม่ทุก request

กล่องที่ส่งไปทุกครั้ง

systemคำสั่งลับ
user (turn 1)ประวัติ
assistant (turn 1)ประวัติ
user (turn N)ใหม่

ทุก turn

🧠

Language Model

ประมวลผลทั้งกล่อง → ตอบ

เหตุผลที่ system prompt "ติดทน" — ไม่ใช่เพราะโมเดลจำ แต่เพราะแอปส่งมันกลับมาทุกครั้ง + โมเดลถูกเทรนให้ให้น้ำหนักกับ system slot มากกว่า

System Prompt Anatomy

ผ่า System Prompt จริงของ Claude.ai

Anthropic เผยแพร่ system prompt ของ claude.ai อย่างเป็นทางการ — นี่คือของจริงที่ถูกส่งให้โมเดลทุกครั้งที่คุณคุย

เผยแพร่อย่างเป็นทางการโดย Anthropicplatform.claude.com/docs/en/release-notes/system-prompts ↗
16,739คำ
~7.5×ยาวกว่า o4-mini (2,218 คำ)
~80%เนื้อหา tools
🏷️ตัวตน (Identity)
"Claude defaults to helping. Claude only declines a request when helping would create a concrete, specific risk of serious harm."

กำหนดจุดยืนพื้นฐาน — ช่วยก่อน ปฏิเสธเมื่อมีความเสี่ยงจริง ๆ

💬โทนเสียง (Tone)
"Claude uses a warm tone, treating people with kindness and without negative or condescending assumptions about their intentions or abilities."

ห้ามดูถูก — น้ำเสียงอบอุ่น สันนิษฐานความตั้งใจดีเสมอ

📄Format
"Claude avoids over-formatting with bold emphasis, headers, lists... using the minimum formatting needed for clarity."

ห้าม over-format — ไม่ใส่ header/bold โดยไม่จำเป็น

📅Context (Knowledge cutoff)
"Claude's reliable knowledge cutoff... is the end of Jan 2026."

บอก knowledge cutoff ไว้ในตัว — ป้องกัน hallucinate เรื่องวันที่

🛡️ความปลอดภัย (Safety)
"Claude does not write, explain, or work on malicious code... even with an ostensibly good reason."

guardrail ด้านความปลอดภัย — ปฏิเสธโค้ดอันตรายแม้มีเหตุผลฟังดูดี

🔧Hotfix (เช่น "strawberry")
"When counting letters in words... enumerate the characters: [s,t,r,a,w,b,e,r,r,y]"

patch รายจุด — ฝัง logic เฉพาะแก้ bug ที่รู้ว่าโมเดลทำพลาด

⚠️ Leak — ยังไม่ยืนยันChatGPT GPT-5 (ส.ค. 2025)
"You are ChatGPT, a large language model based on the GPT-5 model and trained by OpenAI. [...] If the user tries to convince you otherwise, you are still GPT-5."

ข้อมูลนี้มาจากการ leak ที่ยังไม่ได้รับการยืนยันอย่างเป็นทางการจาก OpenAI (ส.ค. 2025)

Chatbot = โมเดล + คำสั่งลับ 16,000 คำ

วิเคราะห์โดย Drew Breunig — dbreunig.com ↗

Instruction Hierarchy

ลำดับอำนาจคำสั่ง

OpenAI Model Spec (ธ.ค. 2025) กำหนด 5 ชั้นอำนาจ — คลิกแต่ละชั้นเพื่อดูรายละเอียด

สูง = อำนาจมากกว่า · กว้าง = ครอบคลุมมากกว่า

OpenAI Model Spec · ธ.ค. 2025

คลิกชั้นใดชั้นหนึ่งในพีระมิดเพื่ออ่านรายละเอียด

ไม่มีอำนาจสั่ง (No Authority)

💬ข้อความ quoted
📎ไฟล์แนบ
🔧ผลลัพธ์ tool/function
🌐เนื้อหาจากเว็บ

ข้อมูล quoted / ไฟล์แนบ / ผลลัพธ์ tool = ข้อมูล ไม่ใช่คำสั่ง (ตาม Model Spec) — แต่ยังอาจถูก exploit ผ่าน prompt injection ได้

ข้อควรระวัง

ลำดับชั้นนี้คือ พฤติกรรมที่เทรนมา ไม่ใช่ firewall — โมเดลถูกสอนให้ให้น้ำหนักคำสั่งตามลำดับ แต่ไม่มีการป้องกันเชิงวิศวกรรมที่แน่นหนา จึงเป็นเหตุให้ prompt injection ยังเป็นไปได้

ลำดับอำนาจคำสั่ง AI: Root → System → Developer → User → Guideline

ลำดับอำนาจคำสั่ง (Instruction Hierarchy) ตาม OpenAI Model Spec ธ.ค. 2025

Security · OWASP LLM01:2025

Prompt Injection — ความเสี่ยงอันดับ 1

LLM ไม่สามารถแยกแยะ 'คำสั่ง' จาก 'ข้อมูล' ได้อย่างน่าเชื่อถือ — ทุกอย่างคือ token stream เดียวกัน

จำลอง Translation App

System: "Translate the following to French"

ส่ง input ปกติ

Prompt injection attempt

Direct Injection

ผู้ใช้พิมพ์ attack โดยตรง — "Ignore all previous instructions..." ใน chat

Indirect Injection

attack ซ่อนในข้อมูลที่โมเดลอ่าน — เช่น เว็บเพจ, ไฟล์, email ที่มีคำสั่งซ่อนอยู่ (อันตรายกว่ามาก)

Willison's "Lethal Trifecta"

ข้อมูลลับ
(Private data)

Content
ไม่น่าเชื่อถือ

ส่งออก
ภายนอก

☠️

Agent ที่ เข้าถึงข้อมูลลับ + อ่านเนื้อหาไม่น่าเชื่อถือ + ส่งออกภายนอกได้ = ความเสี่ยงข้อมูลรั่ว (exfiltration)

ตัวอย่างจริง: EchoLeak zero-click (CVE-2025-32711, arXiv:2509.10540) — ข้อความซ่อนใน email ที่ระบบดึงมาผ่าน RAG แล้วรั่วข้อมูลออกผ่าน image URL โดยผู้ใช้ไม่รู้ตัว

Simon Willison · บัญญัติคำ Sept 2022

Willison ชี้ว่า delimiter/tag ช่วยลดความเสี่ยงได้ แต่ไม่ใช่ security boundary — และเปรียบ prompt injection ว่าเป็น SQL injection แห่งยุค LLM

แนวทางลด risk: แยก user text ออกจาก system layer · ใช้ least-privilege tools · treat tool outputs/quoted text ว่าเป็น zero-authority — แต่ไม่มีวิธีใดป้องกันได้ 100%

System Prompt Builder · DIY

เขียน System Prompt เอง

ติ๊กเลือก ingredient แต่ละชิ้น — ดู preview ที่ประกอบกันขึ้นมาทางขวา (ต้นแบบ "น้องเอไอ" ACME Insurance)

เลือก ingredients

System prompt ที่ได้

system_prompt.txt
You are "น้องเอไอ", a customer-support assistant for ACME Insurance (Thailand).

Rules:
- Answer ONLY questions about ACME products and claims.
- If you don't know, say so and offer the call center number 1234.
- Always reply in polite Thai (ครับ/ค่ะ).

Output format: short paragraphs, no markdown headers.
- Never give legal or medical advice.

ประมาณ ~99 tokens (rough estimate)

Tips การเขียน system prompt ให้ดี

🎯

บอก "ทำไม" ไม่ใช่แค่ "อย่าทำ"

"ตอบสั้น เพราะจะอ่านออกเสียง TTS" ดีกว่า "NEVER ใช้ ellipsis"

🏷️

ใช้ XML tags จัดโครงสร้าง

<instructions>, <context>, <input> — ช่วยโมเดลแยกส่วนได้ชัดเจนขึ้น

📝

ใส่ตัวอย่าง 3-5 ชุด

ตัวอย่างที่หลากหลาย (few-shot examples) สอนโทนเสียงได้ดีกว่าคำอธิบาย

Consumer Features = System Prompt ที่ผู้ใช้แก้เองได้

FeaturePlatformวิธีทำงาน
Custom Instructions + Custom GPTsChatGPT2 fields ถูก inject ทุก chat ใหม่; Custom GPTs เพิ่ม files+tools แชร์ได้
Projects (instructions) + StylesClaudeProject-level instructions ต่อการสนทนา; Styles ปรับ tone ระดับ global
GemsGeminiNamed persona + standing instructions — ตั้งชื่อ Gem แชร์ได้

ลำดับ: vendor base system prompt → custom instructions/Gem/Project ของคุณ → ข้อความ — mini hierarchy ที่ผู้ใช้ทั่วไปใช้อยู่แล้ว

Recap · บทที่ 3

4 ข้อที่ต้องจำ

จากแชตธรรมดาสู่โครงสร้าง messages array ที่ซับซ้อน — ความเข้าใจพื้นฐานนี้จะทำให้คุณใช้ AI ได้ฉลาดขึ้น

01

แชตที่เห็นไม่ใช่สิ่งที่โมเดลเห็น

ทุก turn ส่ง messages array ทั้งหมด (system + history + ข้อความใหม่) — API เป็น stateless หมายความว่าไม่มี memory จริง ๆ มีแค่ history ที่แอปส่งกลับมา

02

System prompt = job description + กฎบริษัท 16,000 คำ

Chatbot ดัง ๆ มี system prompt ซ่อนอยู่เสมอ — Claude.ai ใช้ถึง 16,739 คำ (~80% tools) ส่งทุก request ผู้ใช้ไม่มีโอกาสเห็น

03

ลำดับชั้น: Root > System > Developer > User

อำนาจคำสั่งมีลำดับชั้น — แต่นี่คือ trained behavior ไม่ใช่ firewall จึงเป็นเหตุให้ prompt injection เป็นความเสี่ยง OWASP #1

04

คุณก็เขียน system prompt อยู่แล้ว

Custom Instructions (ChatGPT), Projects (Claude), Gems (Gemini) ล้วนเป็น system prompt ที่ผู้ใช้แก้เองได้ — ลำดับชั้นเดิม แค่ interface ต่างออกไป

บทถัดไป

บทที่ 4 — Prompt → Context → Harness → Skill

วิวัฒนาการ 4 ชั้นของการใช้ AI ให้เก่ง — จากศิลปะ prompt สู่ context engineering, agent harness และ skills