Tag
This paper formalizes the impossibility of perfect prompt-injection prevention in shared-embedding sequence models, proving that no in-pipeline mechanism can guarantee Semantic-Faithful Control due to inseparable representations of instructions and data, analogous to code-data confusion in Von Neumann architectures.