What matters for this injection strategy to work is to follow quite closely the style of the reasoning. It's particularly effective if you copy reasoning from the same context. If you cannot see the reasoning, you cannot duplicate it's style.
That said, including instances of the attack in training is already a good countermeasure.
That said, including instances of the attack in training is already a good countermeasure.