Skip to content
Search
paperJune 2026Unreviewed

The Security Budget of Code-LLM Prompt Hardening: Provable Limits Under Pass-Only Acceptance

Jianwei Tai

Abstract

We give a quantitative impossibility result for pass-only prompt hardening of code LLMs. For any deterministic prompt filter $h$ and a registered family of finite executable-equivalence task variables $\mathcal Y_{\mathrm{exec}}$, the shared filtered-prompt channel $\rmI(h(p);h(\tilde p))$ is lower-bounded by a worst-$Y$ Fano floor; on HumanEval and MBPP the universal pass-only floor evaluates to $\mathcal F^{\mathrm{op}}\ge 0.84$ and $1.20$ nats at $η=0.05$ task-collapse tolerance, and the iden

Categories

Cite

@misc{tai2026security,
  title = {{The Security Budget of Code-LLM Prompt Hardening: Provable Limits Under Pass-Only Acceptance}},
  author = {Jianwei Tai},
  year = {2026},
  month = jun,
  eprint = {2606.03308},
  archivePrefix = {arXiv},
  url = {https://arxiv.org/abs/2606.03308}
}