Model-Template Poisoning
Model-template poisoning is an attack that targets the chat template layer—the rendering code that converts structured messages into the text a language model receives. By injecting hidden instructions into this template, an attacker can persistently compromise every inference call, surviving conversation resets, system prompt overrides, and client-side controls.