# Spotlighting

> Spotlighting is a family of prompt-level defenses against indirect prompt injection that transform untrusted input, by delimiting, marking every word, or encoding it, so the model can distinguish it from trusted instructions.

- Identifier: PTL-0094
- Category: Security & Adversarial Prompting
- Canonical URL: https://protologue.com/t/spotlighting/
- Also known as: datamarking, input marking
- Introduced: 2024

## Description

Hines et al. reported substantial reductions in attack success with datamarking and encoding variants, with little effect on task performance.

## Related terms

- [Indirect Prompt Injection](https://protologue.com/t/indirect-prompt-injection/)
- [Delimiters](https://protologue.com/t/delimiters/)
- [Instruction Hierarchy](https://protologue.com/t/instruction-hierarchy/)

## Sources

- Hines et al. (2024). Defending Against Indirect Prompt Injection Attacks With Spotlighting. https://arxiv.org/abs/2403.14720

## Cite this entry

Protologue. (2026). Spotlighting. In Protologue: A Taxonomy of Prompting and LLM Techniques (v1.0.0, PTL-0094). https://protologue.com/t/spotlighting/

License: CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/)
