Abstract
Large language models (LLMs) that integrate multiple input roles (e.g., system instructions, user queries, external tool outputs) are increasingly prevalent in practice. Ensuring that the model accurately distinguishes messages from each role -- a concept we call *role separation* -- is crucial for consistent multi-role behavior. Although recent work often targets state-of-the-art prompt injection