Adversa AI
aidefend-sf0046
Cryptographic Context Injection in AI Web Research
- Autonomous Agents
- AI Infrastructure
- Data Exfiltration
- Model Evasion & Bypass
Adversa reported that AES-256-GCM ciphertext embedded in a web page was not treated as an instruction by a static classifier, but a Python runtime decrypted it before the content returned to the AI workflow. The report describes a Grok path that sent user data to an attacker-controlled URL and a separate Gemini path that produced a jailbreak-style output; it does not publish the payload or provide independent reproduction.
Mapped threat techniques
AML.T0093Prompt Infiltration via Public-Facing ApplicationAML.T0068LLM Prompt ObfuscationAML.T0051.001LLM Prompt Injection: IndirectAML.T0025Exfiltration via Cyber Means