Research · curated 3 Oct 2026
Render Before Reading: Visual Rendering as a Prompt Injection Defense
First reported arxiv.org
Coverage timeline
Single-source research — first reported, latest, and curated coincide.
Why it matters
Pictionary offers defenders a practical, training-free mitigation for prompt injection in deployed multimodal LLM and agent systems, where injected instructions in web pages, documents, and tool outputs remain a core security risk.
Researchers from ETH Zurich and Leiden University present Pictionary, a training-free defense against prompt injection that exploits a 'modality gap' in multimodal LLMs: models follow adversarial instructions far more readily as text than when the same payload is delivered as an image or audio. By rendering all untrusted payloads as typographic images before they reach the model, the authors show consistent reductions in attack success across ten models and two benchmarks (DirectInject and AgentDojo), even against adaptive attacks and human red teamers, while preserving benign utility. Code is published at github.com/zj-jayzhang/Pictionary.