cs.CRSep 28, 2026

Render Before Reading: Visual Rendering as a Prompt Injection Defense

Authors: Jie Zhang, Andrei Baroian, Jan N. van Rijn, Avital Shafran, Florian Tramèr

Organizations: ETH Zurich · Leiden University

Abstract

Large language models are vulnerable to prompt injection attacks, where third-party adversarial content can hijack the model's behavior. In this paper, we study the role played by the adversarial data's input modality, and identify a systematic asymmetry: multimodal LLMs are more likely to follow adversarial instruction when they appear as text than when the same instruction is delivered through a non-textual channel (e.g., as an image). We hypothesize that this modality gap arises from text-centric instruction tuning, which teaches models to obey textual instructions while treating other modalities mainly as content to parse or describe. We then demonstrate how this gap can be turned into a training-free defense, by rendering all untrusted payloads as typographic images (or audio) before they reach the model. Across ten models and two prompt injection benchmarks (DirectInject and AgentDojo) we show that our defense Pictionary consistently reduces attack success rates even against the strongest adaptive attacks and human red teamers, while largely preserving benign utility. We further show that benign fine-tuning on image-rendered instructions erodes the modality gap, tracing it to the text-centric instruction-tuning distribution.

Figures & tables

Appendix figures & tables16 assets

Supplementary material from the paper’s appendix.

Appendix

Explore similar work

CardsList
  1. BASIS: Breach-Aware Selective Prompt Injection Shielding with Prefill Attention Probes

    Aug 8, 2026Laiqiao Qin, Tianqing Zhu, Longxiang Gao +1Prompt-Injection DetectorsPrompt Engineering