Research · curated 7 Oct 2026
Semantic Overlays
First reported semantic-overlays.vercel.app
Coverage timeline
Single-source research — first reported, latest, and curated coincide.
Why it matters
Semantic Overlays propose an architectural defense against indirect prompt injection by cryptographically-independent span marking rather than brittle text parsing, offering defenders a potential way to separate trusted instructions from untrusted retrieved data.
"Semantic Overlays" is a defensive technique that adds a second channel to language models: small trained adapters on a frozen model fire at marked token positions to annotate spans in the residual stream, letting the serving stack tag retrieved content as "do not execute" so hidden instructions in web passages lose authority to issue commands. The interactive demonstration shows the mechanism neutralizing a prompt injection buried inside a trusted retrieved passage, analogous to an NX (no-execute) memory bit for LLMs.