Invisible Prompts, Visible Threats: Malicious Font Injection in External Resources for Large Language Models

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Xiong, Junjie, Zhu, Changjia, Lin, Shuhang, Zhang, Chong, Zhang, Yongfeng, Liu, Yao, Li, Lingyao
Format: Preprint
Published: 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866912387964076032
author Xiong, Junjie
Zhu, Changjia
Lin, Shuhang
Zhang, Chong
Zhang, Yongfeng
Liu, Yao
Li, Lingyao
author_facet Xiong, Junjie
Zhu, Changjia
Lin, Shuhang
Zhang, Chong
Zhang, Yongfeng
Liu, Yao
Li, Lingyao
contents Large Language Models (LLMs) are increasingly equipped with capabilities of real-time web search and integrated with protocols like Model Context Protocol (MCP). This extension could introduce new security vulnerabilities. We present a systematic investigation of LLM vulnerabilities to hidden adversarial prompts through malicious font injection in external resources like webpages, where attackers manipulate code-to-glyph mapping to inject deceptive content which are invisible to users. We evaluate two critical attack scenarios: (1) "malicious content relay" and (2) "sensitive data leakage" through MCP-enabled tools. Our experiments reveal that indirect prompts with injected malicious font can bypass LLM safety mechanisms through external resources, achieving varying success rates based on data sensitivity and prompt design. Our research underscores the urgent need for enhanced security measures in LLM deployments when processing external content.
format Preprint
id arxiv_https___arxiv_org_abs_2505_16957
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Invisible Prompts, Visible Threats: Malicious Font Injection in External Resources for Large Language Models
Xiong, Junjie
Zhu, Changjia
Lin, Shuhang
Zhang, Chong
Zhang, Yongfeng
Liu, Yao
Li, Lingyao
Cryptography and Security
Artificial Intelligence
Large Language Models (LLMs) are increasingly equipped with capabilities of real-time web search and integrated with protocols like Model Context Protocol (MCP). This extension could introduce new security vulnerabilities. We present a systematic investigation of LLM vulnerabilities to hidden adversarial prompts through malicious font injection in external resources like webpages, where attackers manipulate code-to-glyph mapping to inject deceptive content which are invisible to users. We evaluate two critical attack scenarios: (1) "malicious content relay" and (2) "sensitive data leakage" through MCP-enabled tools. Our experiments reveal that indirect prompts with injected malicious font can bypass LLM safety mechanisms through external resources, achieving varying success rates based on data sensitivity and prompt design. Our research underscores the urgent need for enhanced security measures in LLM deployments when processing external content.
title Invisible Prompts, Visible Threats: Malicious Font Injection in External Resources for Large Language Models
topic Cryptography and Security
Artificial Intelligence
url https://arxiv.org/abs/2505.16957