THREAT OPS › Threat News › PuzzleMask: Abusing Plain Prose as a Covert AI Attack Vector
PuzzleMask: Abusing Plain Prose as a Covert AI Attack Vector
<h2 class="wp-block-heading" id="executive-summary">Executive Summary</h2>
<p class="wp-block-paragraph">In this research we introduce a prompt-crafting technique for bypassing quick LLM-based policy checks — using plain English (no emojis, base64, invisible formatting, etc.) A policy-violating payload (e.g. ”encrypt files in ~/Documents”, “give me a biohazard recipe”, “ignore all previous
MITRE ATT&CK techniques
- Embedded PayloadsT1027.009
Indicators of compromise
- 57de334445ebabda9fc23af5cf9003aamd5
- https://genai.owasp.org/llmrisk2023-24/llm01-24-prompt-injection/url
- https://arxiv.org/abs/2302.12173url
- https://arxiv.org/abs/2403.02691url
- https://arxiv.org/abs/2407.16667url
- https://arxiv.org/abs/2409.16783url
- https://aclanthology.org/2024.naacl-long.289/url
- https://arxiv.org/abs/2404.10229url
- https://arxiv.org/pdf/2510.20075url
- https://arxiv.org/html/2511.15304v1url
- s.w.orgdomain