{
  "id": "spotlighting",
  "code": "PTL-0094",
  "term": "Spotlighting",
  "aliases": [
    "datamarking",
    "input marking"
  ],
  "category": "security",
  "definition": "Spotlighting is a family of prompt-level defenses against indirect prompt injection that transform untrusted input, by delimiting, marking every word, or encoding it, so the model can distinguish it from trusted instructions.",
  "description": "Hines et al. reported substantial reductions in attack success with datamarking and encoding variants, with little effect on task performance.",
  "example": null,
  "broader": [],
  "narrower": [],
  "related": [
    "indirect-prompt-injection",
    "delimiters",
    "instruction-hierarchy"
  ],
  "introduced": 2024,
  "sources": [
    {
      "title": "Defending Against Indirect Prompt Injection Attacks With Spotlighting",
      "authors": "Hines et al.",
      "year": 2024,
      "url": "https://arxiv.org/abs/2403.14720"
    }
  ],
  "url": "https://protologue.com/t/spotlighting/",
  "citation": "Protologue. (2026). Spotlighting. In Protologue: A Taxonomy of Prompting and LLM Techniques (v1.0.0, PTL-0094). https://protologue.com/t/spotlighting/"
}