[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"branding":3,"analytics":7,"article-one-reserved-token-explains-why-chat-injection-attacks-work":10,"sections":45},{"siteName":4,"siteTagline":5,"publisherName":4,"contactEmail":6},"The Revision","Tech news, decoded.","editor@therevision.news",{"gaMeasurementId":8,"adsenseClientId":9},"G-ZW2MV82GYR","ca-pub-8533917693782264",{"article":11},{"id":12,"slug":13,"title":14,"dek":15,"body_md":16,"tags_json":17,"published_at":18,"created_at":19,"updated_at":20,"status":21,"review_note":22,"review_notes":23,"image_url":22,"persona_id":22,"persona_name":22,"section":34,"tags":35,"sources":40,"feedback":44,"feedback_at":22,"cost_usd":44,"total_tokens":44},8565,"one-reserved-token-explains-why-chat-injection-attacks-work","One Reserved Token Explains Why Chat Injection Attacks Work","A new preprint finds a single learned token, not clever wording, powers chat-template prompt injection, and the standard fix misses most popular models.","A forged chat-template marker doesn't need clever wording to hijack an AI agent - it just needs to look official to the tokenizer.\n\nResearchers behind a new preprint, posted to arXiv this month as Same Bytes, Different Authority (arXiv:2609.35932), tested how much of a prompt injection's power comes from the model's own control tokens rather than the words around them. A forged marker, like a fake assistant turn, can reach a model either as one reserved control token or as a string of ordinary subwords that decode to identical text, and it's the server, not the attacker, that decides which one gets sent. Swapping the reserved token for its subword equivalent, with the visible text held constant, cut attack success on the InjecAgent benchmark by 39 to 66 percentage points across three of four open-weight model families, and the effect carried over to multi-turn tasks in AgentDojo. Qwen3-8B was the outlier: it caught the forged turn through its own reasoning even without the special token, until the researchers suppressed that reasoning step, which widened the gap to 50 points.\n\nThat points to a narrow, fixable failure: the injected instruction's authority lives almost entirely in one learned vector tied to the marker's position, not the surrounding text, and instruction tuning makes models trust that vector more, not less. But the paper also finds the standard fix - forcing tokenizers to treat special tokens as plain subwords - only covers tokens a given configuration bothers to declare special. In 33 of 67 tokenizer setups, spanning 255 of the 400 most-downloaded chat models on Hugging Face, the tool-protocol tokens agents use to read tool output are left untouched, so the attack keeps working through that channel.\n\nIt's a reminder that most prompt-injection defenses have been policing the words attackers use, when the model may be listening to something else entirely: the punctuation of its own training.","[\"prompt injection\",\"ai security\",\"ai agents\",\"tokenization\"]","2026-09-30T04:00:00.000Z","2026-09-30T11:42:42.290Z","2026-09-30T11:42:45.944Z","published",null,[24,30],{"id":25,"reviewer":26,"round":27,"reason":28,"status":29},"editor-r1","editor",1,"Attribute the findings to their actual source — this is an arXiv preprint (arXiv:2609.35932v1), not peer-reviewed research — and say so explicitly instead of the vague 'a new study,' since all the cited figures currently lack any named source or publication.","resolved",{"id":31,"reviewer":26,"round":32,"reason":33,"status":29},"editor-r2",2,"Drop the specific claim that the preprint was 'posted September 30' — the source material only provides the arXiv ID (which encodes year\u002Fmonth, not day) with no explicit posting date, so citing an exact day is an unsupported invented detail; state only the arXiv ID and peer-review status, or say 'posted this month.'","security",[36,37,38,39],"prompt injection","ai security","ai agents","tokenization",[41],{"name":42,"url":43},"arXiv cs.AI","https:\u002F\u002Farxiv.org\u002Fabs\u002F2609.35932",0,{"sections":46},[47,51,54,58,63,68,73,78,83,87,92,97,102,107],{"name":48,"slug":49,"count":50,"latest_published_at":18},"AI","ai",5104,{"name":52,"slug":34,"count":53,"latest_published_at":18},"Security",785,{"name":55,"slug":56,"count":57,"latest_published_at":18},"Policy","policy",417,{"name":59,"slug":60,"count":61,"latest_published_at":62},"Deals","deals",284,"2026-09-29T21:00:00.000Z",{"name":64,"slug":65,"count":66,"latest_published_at":67},"Hardware","hardware",194,"2026-09-29T13:16:04.000Z",{"name":69,"slug":70,"count":71,"latest_published_at":72},"Science","science",154,"2026-09-28T13:19:18.000Z",{"name":74,"slug":75,"count":76,"latest_published_at":77},"Consumer Tech","consumer-tech",142,"2026-09-29T18:38:03.000Z",{"name":79,"slug":80,"count":81,"latest_published_at":82},"Software","software",91,"2026-09-25T20:55:00.000Z",{"name":84,"slug":85,"count":86,"latest_published_at":18},"Dev Tools","dev-tools",90,{"name":88,"slug":89,"count":90,"latest_published_at":91},"Startups","startups",83,"2026-09-29T21:51:36.000Z",{"name":93,"slug":94,"count":95,"latest_published_at":96},"General","general",49,"2026-09-28T16:44:57.000Z",{"name":98,"slug":99,"count":100,"latest_published_at":101},"Gaming","gaming",48,"2026-09-25T18:35:21.000Z",{"name":103,"slug":104,"count":105,"latest_published_at":106},"Reviews","reviews",31,"2026-09-28T14:31:34.000Z",{"name":108,"slug":109,"count":110,"latest_published_at":111},"How-To","how-to",6,"2026-06-16T09:00:00.000Z"]