Spotlighting
Also called datamarking, input marking.
Spotlighting is a family of prompt-level defenses against indirect prompt injection that transform untrusted input, by delimiting, marking every word, or encoding it, so the model can distinguish it from trusted instructions.
Description
Hines et al. reported substantial reductions in attack success with datamarking and encoding variants, with little effect on task performance.
Sources
- Hines et al. (2024). Defending Against Indirect Prompt Injection Attacks With Spotlighting.
Cite this entry
Protologue. (2026). Spotlighting. In Protologue: A Taxonomy of Prompting and LLM Techniques (v1.0.0, PTL-0094). https://protologue.com/t/spotlighting/
BibTeX
@misc{protologue_spotlighting,
title = {Spotlighting},
author = {{Protologue}},
year = {2026},
howpublished = {Protologue: A Taxonomy of Prompting and LLM Techniques, v1.0.0},
note = {Entry PTL-0094},
url = {https://protologue.com/t/spotlighting/}
}