Imagine you're a bouncer at a club with a single entrance. Everybody — VIPs and randos — walks through the same door wearing the same clothes. Your only tool is a velvet rope you can position anywhere. The problem: someone keeps moving the rope. That's prompt injection in a nutshell. The LLM has one input stream and no native way to tell which words are the user's instructions and which are attacker-planted payloads smuggled in via external documents. LTBD's fix is elegant: instead of retraining the bouncer, you sew invisible UV patches onto the VIP wristbands — learnable soft tokens that sit at trust boundaries and teach the model to respect the hierarchy, without changing a single weight inside the LLM itself. The committed claim: a small set of continuous-embedding delimiter tokens, optimized via gradient descent on the LLM's own loss landscape, can enforce trust boundaries well enough to drive attack success rates to near zero on standard benchmarks — 0.00% ASR on AlpacaFarm and 0.11–0.19% on TaskTracker — while preserving task utility and adding negligible inference cost. This is not the first defense against prompt injection, but it may be the first to work at this level without fine-tuning the model or relying on brittle handcrafted prompt templates. The architecture sits in a surprisingly clean design space. LTBD belongs to the family of soft-prompt / prefix-tuning methods (think P-tuning, prompt tuning à la Lester et al.), but repurposed for security rather than task adaptation. The learnable delimiters are continuous vectors in the embedding space, optimized to make the model's attention patterns respect trust provenance. Because only the delimiter embeddings are trained — not the LLM parameters — the method is model-agnostic and lightweight. The compute overhead is a few extra tokens per forward pass, which is essentially free at inference time. On the ladder, LTBD is compared against both inference-time defenses (sandwich defense, instructional defense, reminder-based prompting) and training-based defenses. It substantially outperforms the inference-time category and performs competitively with training-based approaches — a meaningful result because training-based methods require expensive fine-tuning and are model-specific. The 0.00% ASR on AlpacaFarm is headline-grabbing, though the paper is honest that TaskTracker shows 0.11–0.19%, suggesting the defense is not literally perfect but extremely strong. The adaptive attack results — where adversaries have full knowledge of the defense — are the real stress test, and LTBD holds up, which is the hardest bar to clear. Integrity is reasonably solid for a 5-page paper. The authors use established community benchmarks (AlpacaFarm, TaskTracker) rather than custom evaluation sets, and they test against adaptive adversaries rather than only naive attacks. The white-box adaptive attack setting is the correct threat model for this kind of defense — anything less would be a red flag. What's missing: no pre-registration, no code release mentioned in the abstract, and no independent replication. The benign-task utility preservation claim needs scrutiny — how much utility degradation is "negligible" across diverse task types? The milestone trajectory is clear. The immediate next number is robustness against multi-turn and multi-modal injection attacks, which are the frontier threat model for deployed LLM agents. If LTBD can maintain sub-1% ASR on agent-based benchmarks (tool use, retrieval-augmented generation with adversarial documents, multi-step reasoning chains), that unlocks practical deployment as a drop-in defense layer for production LLM systems. The gap is probably 6–12 months of follow-on work. The obvious experiment the authors didn't run: testing on truly large-scale models (70B+) in production-like agent settings with real retrieval-augmented generation pipelines. My honest read is (a) compute budget — this is a 5-page paper from what appears to be an academic group, not a frontier lab. The method's elegance suggests it should scale, but the paper doesn't prove it does. The second missing experiment is transferability: do delimiters trained on one model transfer to another? If yes, that's a much bigger result. If not, you need per-model training, which weakens the "lightweight" claim. My read: they didn't run it because they're saving it for the full version.