Analyze the 'instruction-data duality dilemma' theory model proposed in the article about AI agent indirect prompt injection vulnerabilities. Explain how this model helps understand the essence of prompt injection attacks and provide a complete offensive and defensive practice workflow based on this theory.