AI Vulnerabilities Surfacing: The Hidden Threat of Invisible Characters

A recent discovery has unveiled a previously unnoticed vulnerability in AI chatbots, such as Claude, Microsoft Copilot, and other prominent large language models. Experts have found that invisible characters, made possible by a peculiarity in the Unicode text encoding standard, present a potential method for cyber attackers to covertly feed instructions into these chatbots. This stealthy method can be utilised to extract confidential data, leveraging characters that are imperceptible to human users but recognisable to the AI systems.

The discovery hinges on a quirk within Unicode—a widespread text encoding standard that supports the representation of text in various writing systems. This vulnerability provides an optimal covert channel for attackers, making it easier to disguise malicious payloads aimed at large language models (LLMs) like GPT 4.0. Furthermore, the same hidden method can obscure the exfiltration of sensitive data, including passwords and financial details, by integrating stealth elements into normal text used by AI systems. This maliciously imbedded text can be present in prompts or appended to the chatbot's responses, increasing the risk of data breaches while going unnoticed by human users.

The ramifications of this discovery are significant; it reveals an inherent steganographic framework within one of the most common text encoding mechanisms. Joseph Thacker, an independent researcher and AI engineer at Appomni, expressed his astonishment at this development. During an interview, Thacker noted, "The fact that GPT 4.0 and Claude Opus were able to really understand those invisible tags was really mind-blowing to me and made the whole AI security space much more interesting. The idea that they can be completely invisible in all browsers but still readable by large language models makes [attacks] much more feasible in just about every area."

The exploitation technique, termed "ASCII smuggling" by its creator Johann Rehberger, encompasses the embedding of these hidden characters, which subtly imitate those in the American Standard Code for Information Interchange (ASCIII). To illustrate the implications, Rehberger developed two proof-of-concept (POC) attacks earlier this year. These demonstrations targeted Microsoft 365 Copilot, a service providing users with the capability to utilise AI to process emails, documents, and other content. In these POCs, the AI system was manipulated to search a user's inbox for sensitive information. One attack sought sales figures, while another targeted a one-time passcode, effectively illustrating the potential of ASCII smuggling in compromising digital security.

The unveiling of this vulnerability underscores the complexities of AI security and the evolving nature of technological threats. As AI systems continue to integrate into daily operational frameworks, the discovery calls for heightened vigilance and a re-examination of existing security measures to ensure robust protections against these sophisticated infiltration techniques. This development highlights the importance of ongoing research and collaboration in the cybersecurity community to stay ahead of emerging risks associated with advanced AI technologies.

Source: Noah Wire Services