Нотатки: механізм атаки

Робочі нотатки дослідження з посиланнями.

Indirect Prompt Injection via LinkedIn Profiles, Job Postings, Messages, Comments

Research date: 2026-10-01. Scope: technical mechanism of indirect prompt injection (IPI) when AI recruiter, LLM assistant, browser agent, or AI sourcing tool ingests LinkedIn text containing attacker instructions. All facts carry URLs; unverified items are moved to Gaps.

Key Question 1: What is indirect prompt injection, how does it differ from direct, and why does LLM architecture make it possible?

Takeaway

Indirect prompt injection is an attack where the attacker hides instructions inside content that an LLM-powered system later retrieves (a webpage, document, or LinkedIn profile) instead of typing them into the chat window. It works because LLMs have no architectural separation between operator instructions and ingested data: both enter the same context window as natural-language tokens.

Cited Findings

Inferences

Gaps

Key Question 2: Which LinkedIn surfaces can carry a payload?

Takeaway

Practically every free-text or media field of a LinkedIn profile, plus content the user only partially controls (comments, recommendations, tagged posts), is a documented payload carrier. The About/bio section is confirmed used in the wild (May 2026 incident); profile/banner images are a vector against vision-capable scrapers.

Cited Findings

Inferences

Gaps

Key Question 3: Concrete hiding techniques documented in research or writeups

Takeaway

Documented concealment spans four families: invisible Unicode (tag characters U+E0000 to E007F, zero-width characters, RTL overrides, homoglyphs), rendering tricks that humans cannot see but text extraction or OCR still reads (minimum font size and opacity in PDFs, white-on-white text, minuscule font), structural tricks (repeated benign-sounding phrases, spoofed JSON/system roles), and payload in images plus multilingual translation to slip past English-focused filters.

Cited Findings

Inferences

Gaps

Key Question 4: What can the payload make a compromised AI assistant do?

Takeaway

Documented capabilities split into information theft (system prompts, candidate evaluations, conversation content, CRM data), action abuse on the user's behalf (sending messages, booking meetings, purchases, deletions), and decision manipulation (forcing a "perfect candidate" verdict), plus quieter poisoning of aggregated outputs such as company intelligence reports.

Cited Findings

Inferences

Gaps

Key Question 5: Known academic anchors

Takeaway

Two peer-reviewed anchors cover the field: Greshake et al. 2023 (origin of the indirect prompt injection threat model, IEEE-recognized researchers from CISPA/Saarland) and a USENIX Security 2026 paper that is the first systematic study of prompt injection in a real-world recruitment platform (200,000 hireEZ resumes, 1% injected). OWASP LLM01 is the industry-standard reference.

Cited Findings

Inferences

Gaps

← До змісту дослідження