ご案内 入会して研究会活動をもっとお得に!研究会参加費・年間登録費が会員価格になります。
お知らせ 【重要】研究会参加費の支払いおよび原稿アップロード手続きの変更に関するご案内
電子情報通信学会 研究会発表申込システム
講演論文 詳細
技報閲覧サービス
[ログイン]
技報アーカイブ
 トップに戻る 前のページに戻る   [Japanese] / [English] 

講演抄録/キーワード
講演名 2026-03-04 14:50
文書構造を悪用したInvisible Prompt Injection攻撃と自律型AI Agentにおける情報漏洩リスク評価
福田柊友武仲正彦長崎県立大ICSS2025-134
抄録 (和) 近年,大規模言語モデル(LLM)は文書要約や情報整理に広く利用されている一方,入力に埋め込まれた命令を誤って実行する Prompt Injection が深刻なセキュリティ課題となっている.本研究は,間接攻撃の一種であるInvisible Prompt Injection に着目し,Microsoft Word 文書におけるレイヤー構造に着目し,人間の視覚と LLM の文書解析処理の乖離を悪用した攻撃手法を提案する.画像オブジェクトの背面に命令文を配置することで,人間には無害に見える文書に不可視の命令を埋め込み,LLM にのみ実行させる.13 種類の攻撃用 Word ファイルを作成し,主要商用 LLM に対して Black-box 環境で評価した結果,軽量モデルは単純な命令上書きに高い脆弱性を示し,高性能モデルであっても特定の論理構成を持つ不可視プロンプトにより防御が突破される事例を確認した.さらに自律型 AI Agent 環境において,文書内に隠蔽された命令がユーザの意図しないメール要約および外部送信を誘発し得ることを実証し,Human-in-the-loop を前提とした従来対策の限界を明らかにする. 
(英) Large language models (LLMs) have been widely used for document summarization and information organization in recent years. However, prompt injection, in which LLMs mistakenly execute commands embedded in the input, has become a serious security issue. This research focuses on invisible prompt injection, a type of indirect attack. Leveraging the layered structure of Microsoft Word documents, this study proposes an attack method that exploits the discrepancy between human visual perception and the analysis processes of LLMs when processing documents. By placing command statements behind image objects, invisible commands are embedded within documents that appear harmless to humans but are executed only by LLMs. Thirteen types of attack Word files were created and evaluated against major commercial LLMs in a black-box environment. The results showed that lightweight models were highly vulnerable to simple command overwrites, and even high performance models could be breached by invisible prompts with specific logical structures. Furthermore, in an autonomous AI agent environment, we demonstrate that commands concealed within documents can trigger users to perform unintended email summarization and external transmission, revealing the limitations of conventional countermeasures that rely on human oversight.
キーワード (和) 大規模言語モデル / Invisible Prompt Injection / AI Agent / 情報漏洩 / / / /  
(英) Large Language Model / Invisible Prompt Injection / AI Agent / Information Leakage / / / /  
文献情報 信学技報, vol. 125, no. 381, ICSS2025-134, pp. 363-369, 2026年3月.
資料番号 ICSS2025-134 
発行日 2026-02-24 (ICSS) 
ISSN Online edition: ISSN 2432-6380
著作権に
ついて
技術研究報告に掲載された論文の著作権は電子情報通信学会に帰属します.(許諾番号:10GA0019/12GB0052/13GB0056/17GB0034/18GB0034)
PDFダウンロード ICSS2025-134

研究会情報
研究会 ICSS IPSJ-SPT  
開催期間 2026-03-03 - 2026-03-04 
開催地(和) 沖縄県立美術館・博物館 
開催地(英) Okinawa Prefectural Museum & Art Museum 
テーマ(和) セキュリティ,トラスト,一般 
テーマ(英) Security, Trust, etc. 
講演論文情報の詳細
申込み研究会 ICSS 
会議コード 2026-03-ICSS-SPT 
本文の言語 日本語 
タイトル(和) 文書構造を悪用したInvisible Prompt Injection攻撃と自律型AI Agentにおける情報漏洩リスク評価 
サブタイトル(和)  
タイトル(英) Invisible Prompt Injection Attacks Exploiting Document Structure and Information Leakage Risk Assessment in Autonomous AI Agents 
サブタイトル(英)  
キーワード(1)(和/英) 大規模言語モデル / Large Language Model  
キーワード(2)(和/英) Invisible Prompt Injection / Invisible Prompt Injection  
キーワード(3)(和/英) AI Agent / AI Agent  
キーワード(4)(和/英) 情報漏洩 / Information Leakage  
キーワード(5)(和/英) /  
キーワード(6)(和/英) /  
キーワード(7)(和/英) /  
キーワード(8)(和/英) /  
第1著者 氏名(和/英/ヨミ) 福田 柊友 / Hiyu Fukuda / フクダ ヒユウ
第1著者 所属(和/英) 長崎県立大学 シーボルト校 (略称: 長崎県立大)
University of Nagasaki (略称: University of Nagasaki)
第2著者 氏名(和/英/ヨミ) 武仲 正彦 / Masahiko Takenaka / タケナカ マサヒコ
第2著者 所属(和/英) 長崎県立大学 シーボルト校 (略称: 長崎県立大)
University of Nagasaki (略称: University of Nagasaki)
第3著者 氏名(和/英/ヨミ) / /
第3著者 所属(和/英) (略称: )
(略称: )
第4著者 氏名(和/英/ヨミ) / /
第4著者 所属(和/英) (略称: )
(略称: )
第5著者 氏名(和/英/ヨミ) / /
第5著者 所属(和/英) (略称: )
(略称: )
第6著者 氏名(和/英/ヨミ) / /
第6著者 所属(和/英) (略称: )
(略称: )
第7著者 氏名(和/英/ヨミ) / /
第7著者 所属(和/英) (略称: )
(略称: )
第8著者 氏名(和/英/ヨミ) / /
第8著者 所属(和/英) (略称: )
(略称: )
第9著者 氏名(和/英/ヨミ) / /
第9著者 所属(和/英) (略称: )
(略称: )
第10著者 氏名(和/英/ヨミ) / /
第10著者 所属(和/英) (略称: )
(略称: )
第11著者 氏名(和/英/ヨミ) / /
第11著者 所属(和/英) (略称: )
(略称: )
第12著者 氏名(和/英/ヨミ) / /
第12著者 所属(和/英) (略称: )
(略称: )
第13著者 氏名(和/英/ヨミ) / /
第13著者 所属(和/英) (略称: )
(略称: )
第14著者 氏名(和/英/ヨミ) / /
第14著者 所属(和/英) (略称: )
(略称: )
第15著者 氏名(和/英/ヨミ) / /
第15著者 所属(和/英) (略称: )
(略称: )
第16著者 氏名(和/英/ヨミ) / /
第16著者 所属(和/英) (略称: )
(略称: )
第17著者 氏名(和/英/ヨミ) / /
第17著者 所属(和/英) (略称: )
(略称: )
第18著者 氏名(和/英/ヨミ) / /
第18著者 所属(和/英) (略称: )
(略称: )
第19著者 氏名(和/英/ヨミ) / /
第19著者 所属(和/英) (略称: )
(略称: )
第20著者 氏名(和/英/ヨミ) / /
第20著者 所属(和/英) (略称: )
(略称: )
第21著者 氏名(和/英/ヨミ) / /
第21著者 所属(和/英) (略称: )
(略称: )
第22著者 氏名(和/英/ヨミ) / /
第22著者 所属(和/英) (略称: )
(略称: )
第23著者 氏名(和/英/ヨミ) / /
第23著者 所属(和/英) (略称: )
(略称: )
第24著者 氏名(和/英/ヨミ) / /
第24著者 所属(和/英) (略称: )
(略称: )
第25著者 氏名(和/英/ヨミ) / /
第25著者 所属(和/英) (略称: )
(略称: )
第26著者 氏名(和/英/ヨミ) / /
第26著者 所属(和/英) (略称: )
(略称: )
第27著者 氏名(和/英/ヨミ) / /
第27著者 所属(和/英) (略称: )
(略称: )
第28著者 氏名(和/英/ヨミ) / /
第28著者 所属(和/英) (略称: )
(略称: )
第29著者 氏名(和/英/ヨミ) / /
第29著者 所属(和/英) (略称: )
(略称: )
第30著者 氏名(和/英/ヨミ) / /
第30著者 所属(和/英) (略称: )
(略称: )
第31著者 氏名(和/英/ヨミ) / /
第31著者 所属(和/英) (略称: )
(略称: )
第32著者 氏名(和/英/ヨミ) / /
第32著者 所属(和/英) (略称: )
(略称: )
第33著者 氏名(和/英/ヨミ) / /
第33著者 所属(和/英) (略称: )
(略称: )
第34著者 氏名(和/英/ヨミ) / /
第34著者 所属(和/英) (略称: )
(略称: )
第35著者 氏名(和/英/ヨミ) / /
第35著者 所属(和/英) (略称: )
(略称: )
第36著者 氏名(和/英/ヨミ) / /
第36著者 所属(和/英) (略称: )
(略称: )
講演者 第1著者 
発表日時 2026-03-04 14:50:00 
発表時間 20分 
申込先研究会 ICSS 
資料番号 ICSS2025-134 
巻番号(vol) vol.125 
号番号(no) no.381 
ページ範囲 pp.363-369 
ページ数
発行日 2026-02-24 (ICSS) 


[研究会発表申込システムのトップページに戻る]

[電子情報通信学会ホームページ]


IEICE / 電子情報通信学会