structured-separation-needs-training-and-reduces-rather-than-eliminates
mechanismreplicated

Separating instructions from data raises injection resistance substantially, but both published versions get their strength from fine-tuning the model on the separation, and both report improved robustness rather than elimination. Treat it as one layer of defense in depth; the prompt-only variant, without training, has no measured efficacy behind it here.

Capability: Following instructions hidden in data · Security, Autonomous agent

Observed on

2024, GPT-3.5 class and open base models.

Sources

Status: activeLast checked: 2026-09-04Evidence activityHow much the field cites the sources under this claimvery heavily cited in the last 12 months285 in 12mo · 486 total — The Instruction Hierarchy: Training LLMs to Prioritize Privileged Instructions243 in 12mo · 394 total — StruQ: Defending Against Prompt Injection with Structured Queries
Contest this claim

Disagreeing is the most useful thing you can do here. Both sides of every contested claim in this catalog were assembled by the same person, which is its weakest point.

Related claims

Notes

The gap worth being honest about: the technique record describes a prompt-level fallback for people without training access, and neither source evaluates that. So the claim asserts what the papers show (training-based, partial) and marks the untrained variant as unmeasured rather than assuming it inherits the result.