Skip to content
Search
paperJuly 2026Unreviewed

Containment over Detection: Cryptographic Boundary Enforcement for Prompt Injection Defense in Agentic LLM Systems

Saurabh Sharma

Abstract

Abstract Prompt injection—the manipulation of an LLM-based agent through adversarial content embedded in user input—poses a critical security risk in production agentic systems with access to sensitive datastores and code execution environments. Detection-based defenses (keyword filtering, learned classifiers) suffer from a fundamental accuracy–latency tradeoff and fail to address the root cause: the absence of a syntactic boundary between instructions and data in LLM context windows. We present

Categories

Framework mappings

MITRE ATLAS
  • AML.T0051LLM Prompt Injection

Suggested from the entry's categories.

Cite

@misc{sharma2026containment,
  title = {{Containment over Detection: Cryptographic Boundary Enforcement for Prompt Injection Defense in Agentic LLM Systems}},
  author = {Saurabh Sharma},
  year = {2026},
  month = jul,
  doi = {10.21203/rs.3.rs-10196595/v1},
  url = {https://doi.org/10.21203/rs.3.rs-10196595/v1}
}