On the Inseparability of Instructions and Data in Shared-Embedding Sequence Models
Prompt injection is the top security risk for LLM-integrated applications, yet every defense proposed so far has been broken. We prove this is not a coincidence: in shared-embedding architectures that lack enforced control-data separation, perfect prompt-injection prevention is mathematically impossible. We formalize prompted systems as Prompted Action Models whose outputs include control-authoritative actions: refusal decisions, tool authorization, policy routing, and memory writes. We define S
Record details
Published: 25 June 2026
Source: arXiv
Category: Research
Topics: Regulation · Military & security
Retrieved: 14 July 2026
Related evidence
These records share source-supplied organisations, an exact publisher byline, automatic topics or regions. The reason is shown on every link; related does not mean supporting, agreeing with or verifying this record.
Direct Causation in International Humanitarian Law and the Challenge of AI-Mediated Civilian Cyber Operations
arXiv · 28 June 2026
Managed Autonomy at Runtime: Gear-Based Safety and Governance for Single- and Multi-Agent Cyber-Physical Systems
arXiv · 1 July 2026
CEDAR-42001: From ISO/IEC 42001 Conformity to Architecture-Aware, Audit-Visible Assurance Posture for AI Cyber-Physical Systems
arXiv · 19 June 2026
SolarChain-Eval: A Physics-Constrained Benchmark for Trustworthy Economic Agents in Decentralized Energy Markets
arXiv · 9 July 2026
Problem of (In)Explainability in Testing Fully Autonomous Weapon Systems for International Humanitarian Law Compliance
Minds and Machines · 10 July 2026
AI Researchers Must Help Lead Arms Control to Mitigate Military AI Risks
arXiv · 10 June 2026
How to cite this record
ethics.ai (25 June 2026), “On the Inseparability of Instructions and Data in Shared-Embedding Sequence Models,” evidence record 545, https://ethics.ai/record/545 (originally published by arXiv).
Use and limitations
This page is a stable index and citation surface for a source record. ethics.ai did not author the underlying report and has not independently verified every claim. Automatic topics may be imperfect. For consequential use, quote and cite the original publisher.