arXiv:2609.35932v1 Announce Type: new Abstract: Prompt injection against LLM agents becomes much stronger when the injected instruction is wrapped in the model's own chat template. A forged template marker such as can reach the model either as a single reserved control token or as a sequence of ordinary subword tokens.

Read the full article at arXiv cs.CR →