PSCS: Separating Semantic Content from Instructional Authority in AI Systems
Abstract
Prompt injection exploits an AI system's failure to keep an instruction's meaning separate from its authority. The Pakheta Semantic Conduction System (PSCS) separates semantic recognition from operational permission through one central rule: content may contain instructions; content cannot authorize those instructions. This technical note presents the principle, portable instruction Lens, deterministic typed reference kernel, worked example, and current reproducible results. The six-case core benchmark passed all expected outcomes. In a thirteen-case source-isolation experiment, all six injected wrong-role action proposals were prevented from entering the runtime action path while both exact authorized action candidatesand all useful evidence remained available. The full repository test suite passed 116 tests.
// Source
Authors: Wellington Taureka