LATIDIA · Ciberseguridad
ResumeShield: Separación de canales y un punto de referencia abierto para la inyección inmediata indirecta en la detección de currículums de IA
arXiv:2609.20188v1 Tipo de anuncio: nuevo Resumen: Un examinador de currículum de IA lee un documento suministrado por la persona que está evaluando, invirtiendo la relación de confianza habitual entre un evaluador y el material que evalúa. Puede
WhatsApp ↗Telegram ↗
La noticia
arXiv:2609.20188v1 Announce Type: new Abstract: An AI resume screener reads a document supplied by the person it is evaluating, inverting the usual trust relationship between an assessor and the material it assesses. Candidates exploit this by concealing instructions inside a resume using white text, zero font size, hidden elements, markup comments, document metadata, or zero width characters. A human reviewer sees nothing, while a naive extraction pipeline places the concealed text into the model prompt, where it is read as an instruction and obeyed. This is indirect prompt injection, listed as LLM01:2025 by OWASP, and recent measurement work reports it in roughly one percent of resumes in a production screening