Opening SecureFlowAI Recommendation Poisoning via Crafted AI Assistant Links
Case summary & sources

AIDEFEND SecureFlow / SecureFlow Case Index

MITRE ATLAS mitre-atlas-cs0072

AI Recommendation Poisoning via Crafted AI Assistant Links

  • Autonomous Agents
  • Model Poisoning & Integrity

Microsoft reported real-world attempts to influence AI recommendations through links presented as summarization tools. Website operators placed promotional instructions in URL prompt parameters that open an AI assistant. If the assistant accepts those instructions as durable memory, later answers can favor the operator's brand or website. The report identifies more than 50 unique prompts associated with 31 companies across 14 industries; these are attempts, not a count of successful compromises. Effectiveness varies by platform and over time. Its fictional brands and financial-loss examples illustrate possible consequences. The six-step flow follows ATLAS's ordered procedures; the last two steps depend on successful memory acceptance and subsequent recall.

Mapped threat techniques

Source

Updated