arXiv:2605.28999cs.CRcs.AI2026-05被引 2

首次测量简历筛选中大规模提示注入攻击,发现1%简历含隐藏攻击且近年上升。

Measuring Real-World Prompt Injection Attacks in LLM-based Resume Screening

论文配图:Measuring Real-World Prompt Injection Attacks in LLM-based Resume Screening
图 1 · 摘自论文原文
  • 针对简历设计专用检测方法,精度优于现有通用工具。
  • 约1%真实简历含隐藏提示注入,过去1-2年显著增多。
  • 90%以上攻击不使用明确指令,隐蔽性强,适合安全研究者关注。

大型语言模型(LLMs)易受提示注入攻击,但此类漏洞多见于学术概念验证或零星案例,其在真实应用中的普遍性和影响尚不明确。本文首次系统研究了主流应用场景——基于LLM的简历筛选中的提示注入攻击。分析基于hireEZ平台多年收集的约20万份真实简历。我们设计了专用于简历的提示注入检测方法,小规模人工验证显示该方法精度高,优于现有通用检测器。将该检测器应用于全量数据后,发现约1%的简历包含隐藏提示注入;近一至两年内该比例明显上升;超过90%的注入提示未使用显式指令。这些结果首次揭示了真实世界中大规模提示注入的存在,为后续防御研究提供了基础。

原文摘要 · Abstract (English)

LLMs are vulnerable to prompt injection attacks. However, this vulnerability has been primarily demonstrated conceptually in academic studies or through a few anecdotal case studies. Its prevalence and impact in real-world LLM-based applications are largely unexplored. In this work, we present the first systematic study of prompt-injection attacks in a widely used application: LLM-based resume screening. Our analysis is based on approximately 200K real-world resumes collected over multiple years by hireEZ. We first design tailored methods to detect prompt injection in resumes. Manual validation on a small-scale dataset demonstrates that our detectors achieve high precision and outperform state-of-the-art general-purpose detectors. We then apply our detector to the full resume dataset and conduct a comprehensive measurement study of real-world prompt injection attacks. Our analysis reveals several intriguing findings: approximately 1% of resumes contain hidden prompt injections; the prevalence of such injected resumes has increased noticeably over the past one to two years; and more than 90% of injected prompts do not use explicit instructions. These results provide the first evidence of large-scale prompt injection in real-world LLM-based applications and lay the groundwork for future studies to understand and mitigate such attacks.

提示注入简历筛选安全评估真实世界

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。