3 Sources
[1]
New AI attack hides data-theft prompts in downscaled images
Researchers have developed a novel attack that steals user data by injecting malicious prompts in images processed by AI systems before delivering them to a large language model. The method relies on full-resolution images that carry instructions invisible to the human eye but become apparent when
[2]
Hackers can hide AI prompt injection attacks in resized images
A new method of hiding instructions for "AI" systems takes advantage of how images are compressed when uploaded. "AI" tools are all the rage at the moment, even among users who aren't all that savvy when it comes to conventional software or security -- and that's opening up all sorts of new
[3]
New AI attack shows how images hide secret commands, letting hackers siphon private data directly from unsuspecting chatbot users
Bicubic interpolation can expose black text from specially crafted images As AI tools become more integrated into daily work, the security risks attached to them are also evolving in new directions. Researchers at Trail of Bits have demonstrated a method where malicious prompts are hidden inside
Share
Copy Link
Researchers have uncovered a novel attack method that hides malicious prompts in images, which become visible when processed by AI systems, potentially leading to unauthorized data access and theft.
Researchers from Trail of Bits have developed a new attack method that exploits how AI systems process images, potentially leading to unauthorized data access and theft. This technique, building upon a 2020 USENIX paper from TU Braunschweig, hides malicious prompts in images that become visible only when downscaled by AI systems
1
.
Source: BleepingComputer
The attack takes advantage of image resampling algorithms commonly used by AI systems for performance and cost efficiency. When users upload images, these are automatically downscaled, introducing aliasing artifacts that can reveal hidden patterns
1
. Specifically:In one example, dark areas of a malicious image turn red during bicubic downscaling, allowing hidden black text to emerge
2
.
Source: PCWorld
The researchers confirmed this attack method's feasibility against several AI systems, including:
In a proof-of-concept, the researchers successfully exfiltrated Google Calendar data to an arbitrary email address using Zapier MCP with 'trust=True' to approve tool calls without user confirmation
3
.This attack vector is potentially widespread and may extend beyond the tested tools. It raises significant concerns about trust in multimodal AI systems, especially as these platforms become more integrated into daily work routines
3
. The risk of identity theft and unauthorized access to sensitive information is particularly concerning, given that many AI models link with calendars, communications platforms, and workflow tools.Related Stories
To address this vulnerability, Trail of Bits researchers recommend several measures:
1
.
Source: TechRadar
To demonstrate their findings, the researchers created Anamorpher, an open-source tool currently in beta. This tool can create images for each of the mentioned downscaling methods, illustrating the potential for replication of this attack technique
3
.As AI technologies continue to evolve and integrate into various aspects of our digital lives, this research underscores the critical need for robust security measures and user awareness to protect against emerging threats in the AI landscape.
Summarized by
Navi
[1]
15 Sept 2025•Technology

18 Oct 2024•Technology

22 Oct 2025•Technology

1
Technology

2
Policy and Regulation

3
Technology
