June 2026Unreviewed
The Security Budget of Code-LLM Prompt Hardening: Provable Limits Under Pass-Only Acceptance
Jianwei Tai
Abstract
We give a quantitative impossibility result for pass-only prompt hardening of code LLMs. For any deterministic prompt filter $h$ and a registered family of finite executable-equivalence task variables $\mathcal Y_{\mathrm{exec}}$, the shared filtered-prompt channel $\rmI(h(p);h(\tilde p))$ is lower-bounded by a worst-$Y$ Fano floor; on HumanEval and MBPP the universal pass-only floor evaluates to $\mathcal F^{\mathrm{op}}\ge 0.84$ and $1.20$ nats at $η=0.05$ task-collapse tolerance, and the iden
Categories
Cite
@misc{tai2026security,
title = {{The Security Budget of Code-LLM Prompt Hardening: Provable Limits Under Pass-Only Acceptance}},
author = {Jianwei Tai},
year = {2026},
month = jun,
eprint = {2606.03308},
archivePrefix = {arXiv},
url = {https://arxiv.org/abs/2606.03308}
}