Opening SecureFlowCryptographic Context Injection in AI Web Research
Case summary & sources

AIDEFEND SecureFlow / SecureFlow Case Index

Adversa AI aidefend-sf0046

Cryptographic Context Injection in AI Web Research

  • Autonomous Agents
  • AI Infrastructure
  • Data Exfiltration
  • Model Evasion & Bypass

Adversa reported that AES-256-GCM ciphertext embedded in a web page was not treated as an instruction by a static classifier, but a Python runtime decrypted it before the content returned to the AI workflow. The report describes a Grok path that sent user data to an attacker-controlled URL and a separate Gemini path that produced a jailbreak-style output; it does not publish the payload or provide independent reproduction.

Mapped threat techniques

  • AML.T0093 Prompt Infiltration via Public-Facing Application
  • AML.T0068 LLM Prompt Obfuscation
  • AML.T0051.001 LLM Prompt Injection: Indirect
  • AML.T0025 Exfiltration via Cyber Means

Source