Reserved-token embeddings carry prompt injection authority; standard defenses fail on 255 of top 400 chat models

PekingUniversity · hf · 2026-09-30

Peking University researchers dissect chat-template prompt injection: a forged marker like <|imstart|> can reach the model as one reserved control token or as ordinary subwords—identical text, and the server-side tokenizer decides which.

Original post →

More from Safety

Safety channel →