Prompt injection · Microsoft · U.S. · The Information · Ars Technica
Spammers are embedding Unicode in an attempt to evade filters that search for text
Compiled by KHAO Editorial — aggregated from 1 source. See llms.txt for citation guidance.
◌ Single Source
By sprinkling the invisible text into the middle of the word “funding,” for example, filters may read the words “fun” and “ding” instead.
Key facts
- Beginning on one day in early February, the number of ASCII smuggling signatures detected by Microsoft Defender for Office spiked from roughly 21,000 per day to more than 1.3 million
- The block of 128 tags mimics a portion of the American Standard Code for Information Interchange almost perfectly, with one major difference: the characters they encode are readable by computers
- It gained attention two years ago as a means of making a class of AI attack known as prompt injections more stealthy
- Unless a filtering system takes a picture of a message and does OCR extraction over the visual image, it may miss this type of attack
Summary
A clever technique used to hide malicious prompts in attacks on AI agents has been adopted by spammers to evade filters on email platforms that are designed to flag unwanted messages used in mass campaigns. The technique is broadly known as ASCII smuggling. The block of 128 tags mimics a portion of the American Standard Code for Information Interchange almost perfectly, with one major difference: the characters they encode are readable by computers but, by design, are almost completely invisible to humans. Earlier this year, Microsoft started seeing a massive increase in spam messages that used the technique. “Because tag characters are invisible to humans but exist at the text-processing level, the same property that makes them useful for smuggling instructions into a model also makes them useful for obfuscating keywords before a detector evaluates them,” Microsoft explained Thursday.