arXiv:2606.27287cs.AI2026-06ACL

研究大模型简历筛选中提示注入的操纵效果及风险

Prompt Injection in Automated Résumé Screening with Large Language Models: Single and Multi-Injection Settings

论文配图:Prompt Injection in Automated Résumé Screening with Large Language Models: Single and Multi-Injection Settings
图 1 · 摘自论文原文
  • 通过隐性自夸文本影响大模型评分,实现简历排名提升
  • 当候选人水平相近且少数人注入时,效果显著;普遍使用则失效
  • 低质量候选人可能逆袭,引发公平性担忧

大型语言模型(LLMs)正被广泛用于简历筛选与排名,这促使求职者试图策略性地操控算法招聘系统。本文研究了自动化简历筛选中的提示注入问题,即在不新增资质的情况下,通过细微的自我推广文本影响大模型评估。通过受控实验发现,当简历质量相近且少数候选人使用提示注入时,其排名提升效果稳定;但随着注入人数增多,效果迅速下降,普遍使用时完全失效。当候选人质量差异明显时,提示注入平均效果较弱,但仍可能使低质量者超越高质量者,引发公平性问题。总体而言,大模型筛选系统在操纵稀少且候选人能力差异小时最易被攻破。代码与资源已公开于:https://github.com/preetb1199/Prompt_Injection_ACL26

原文摘要 · Abstract (English)

Large language models (LLMs) are increasingly used to screen and rank job applicants, creating incentives for candidates to strategically manipulate algorithmic hiring systems. We study prompt injection in automated résumé screening, defined as subtle self-promotional text that introduces no new qualifications but is designed to influence LLM evaluations. Using controlled experiments, we show that prompt injection reliably improves applicant rankings when résumé quality is homogeneous and few candidates inject. However, its effectiveness rapidly diminishes as more candidates inject, collapsing when manipulation becomes widespread. When candidate quality is heterogeneous, prompt injection is less effective on average, but can occasionally allow lower-quality candidates to outrank higher-quality ones, raising fairness concerns. Overall, LLM-based screening is most vulnerable when manipulation is rare and candidate quality differences are small. Code and resources are publicly available at: https://github.com/preetb1199/Prompt_Injection_ACL26

大模型安全简历筛选提示注入公平性

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。