Skip to content
Search
paperJune 2026Unreviewed

On the Inseparability of Instructions and Data in Shared-Embedding Sequence Models

Dewank Pant, Shruti Lohani, Avijit Kumar

Abstract

Prompt injection is the top security risk for LLM-integrated applications, yet every defense proposed so far has been broken. We prove this is not a coincidence: in shared-embedding architectures that lack enforced control-data separation, perfect prompt-injection prevention is mathematically impossible. We formalize prompted systems as Prompted Action Models whose outputs include control-authoritative actions: refusal decisions, tool authorization, policy routing, and memory writes. We define S

Categories

Framework mappings

MITRE ATLAS
  • AML.T0051LLM Prompt Injection

Suggested from the entry's categories.

Cite

@misc{pant2026inseparability,
  title = {{On the Inseparability of Instructions and Data in Shared-Embedding Sequence Models}},
  author = {Dewank Pant and Shruti Lohani and Avijit Kumar},
  year = {2026},
  month = jun,
  eprint = {2606.27567},
  archivePrefix = {arXiv},
  url = {https://arxiv.org/abs/2606.27567}
}