If an attacker splits a malicious prompt into discrete chunks, some large language models (LLMs) will get lost in the details ...