June 2026Unreviewed
On the Inseparability of Instructions and Data in Shared-Embedding Sequence Models
Dewank Pant, Shruti Lohani, Avijit Kumar
Abstract
Prompt injection is the top security risk for LLM-integrated applications, yet every defense proposed so far has been broken. We prove this is not a coincidence: in shared-embedding architectures that lack enforced control-data separation, perfect prompt-injection prevention is mathematically impossible. We formalize prompted systems as Prompted Action Models whose outputs include control-authoritative actions: refusal decisions, tool authorization, policy routing, and memory writes. We define S
Categories
Framework mappings
OWASP Top 10 for LLM Applications
- LLM01Prompt Injection
MITRE ATLAS
- AML.T0051LLM Prompt Injection
Suggested from the entry's categories.
Cite
@misc{pant2026inseparability,
title = {{On the Inseparability of Instructions and Data in Shared-Embedding Sequence Models}},
author = {Dewank Pant and Shruti Lohani and Avijit Kumar},
year = {2026},
month = jun,
eprint = {2606.27567},
archivePrefix = {arXiv},
url = {https://arxiv.org/abs/2606.27567}
}