Same Bytes, Different Authority: Reserved-Token Representations in Chat-Template Prompt Injection
Factual evidence
What the source reports
Research reveals LLM agent prompt injections gain strength when wrapped in chat templates using reserved-token control markers.
Inspect the evidence
- Inclusion basis
- Enterprise AI
- Publisher and source type
- arXiv cs.LG — Machine Learning · RESEARCH
- Published by source
- 30 September 2026
- Collected by OneBench
- 1 Oct 2026, 03:02 UK
Stored source excerpt
arXiv:2609.35932v1 Announce Type: cross Abstract: Prompt injection against LLM agents becomes much stronger when the injected instruction is wrapped in the model's own chat template.…
Short excerpt from the collected text, not the full source. Use the source link to read it in context.
The factual summary is a OneBench synthesis, not a quotation or independent verification. Collection time is not publication time. Open the source for its full context; related reporting can share the same underlying announcement.
OneBench interpretation
Institutional assessment
So what
Server-side tokenization mechanics allow attackers to trick LLM agents by forging control markers, exposing untrusted input parsing vulnerabilities in financial workflows.
Do what
Review input sanitization and chat-template tokenization logic with the team responsible for LLM agent security.