| 講演抄録/キーワード |
| 講演名 |
2026-03-04 14:50
文書構造を悪用したInvisible Prompt Injection攻撃と自律型AI Agentにおける情報漏洩リスク評価 ○福田柊友・武仲正彦(長崎県立大) ICSS2025-134 |
| 抄録 |
(和) |
近年,大規模言語モデル(LLM)は文書要約や情報整理に広く利用されている一方,入力に埋め込まれた命令を誤って実行する Prompt Injection が深刻なセキュリティ課題となっている.本研究は,間接攻撃の一種であるInvisible Prompt Injection に着目し,Microsoft Word 文書におけるレイヤー構造に着目し,人間の視覚と LLM の文書解析処理の乖離を悪用した攻撃手法を提案する.画像オブジェクトの背面に命令文を配置することで,人間には無害に見える文書に不可視の命令を埋め込み,LLM にのみ実行させる.13 種類の攻撃用 Word ファイルを作成し,主要商用 LLM に対して Black-box 環境で評価した結果,軽量モデルは単純な命令上書きに高い脆弱性を示し,高性能モデルであっても特定の論理構成を持つ不可視プロンプトにより防御が突破される事例を確認した.さらに自律型 AI Agent 環境において,文書内に隠蔽された命令がユーザの意図しないメール要約および外部送信を誘発し得ることを実証し,Human-in-the-loop を前提とした従来対策の限界を明らかにする. |
| (英) |
Large language models (LLMs) have been widely used for document summarization and information organization in recent years. However, prompt injection, in which LLMs mistakenly execute commands embedded in the input, has become a serious security issue. This research focuses on invisible prompt injection, a type of indirect attack. Leveraging the layered structure of Microsoft Word documents, this study proposes an attack method that exploits the discrepancy between human visual perception and the analysis processes of LLMs when processing documents. By placing command statements behind image objects, invisible commands are embedded within documents that appear harmless to humans but are executed only by LLMs. Thirteen types of attack Word files were created and evaluated against major commercial LLMs in a black-box environment. The results showed that lightweight models were highly vulnerable to simple command overwrites, and even high performance models could be breached by invisible prompts with specific logical structures. Furthermore, in an autonomous AI agent environment, we demonstrate that commands concealed within documents can trigger users to perform unintended email summarization and external transmission, revealing the limitations of conventional countermeasures that rely on human oversight. |
| キーワード |
(和) |
大規模言語モデル / Invisible Prompt Injection / AI Agent / 情報漏洩 / / / / |
| (英) |
Large Language Model / Invisible Prompt Injection / AI Agent / Information Leakage / / / / |
| 文献情報 |
信学技報, vol. 125, no. 381, ICSS2025-134, pp. 363-369, 2026年3月. |
| 資料番号 |
ICSS2025-134 |
| 発行日 |
2026-02-24 (ICSS) |
| ISSN |
Online edition: ISSN 2432-6380 |
著作権に ついて |
技術研究報告に掲載された論文の著作権は電子情報通信学会に帰属します.(許諾番号:10GA0019/12GB0052/13GB0056/17GB0034/18GB0034) |
| PDFダウンロード |
ICSS2025-134 |
| 研究会情報 |
| 研究会 |
ICSS IPSJ-SPT |
| 開催期間 |
2026-03-03 - 2026-03-04 |
| 開催地(和) |
沖縄県立美術館・博物館 |
| 開催地(英) |
Okinawa Prefectural Museum & Art Museum |
| テーマ(和) |
セキュリティ,トラスト,一般 |
| テーマ(英) |
Security, Trust, etc. |
| 講演論文情報の詳細 |
| 申込み研究会 |
ICSS |
| 会議コード |
2026-03-ICSS-SPT |
| 本文の言語 |
日本語 |
| タイトル(和) |
文書構造を悪用したInvisible Prompt Injection攻撃と自律型AI Agentにおける情報漏洩リスク評価 |
| サブタイトル(和) |
|
| タイトル(英) |
Invisible Prompt Injection Attacks Exploiting Document Structure and Information Leakage Risk Assessment in Autonomous AI Agents |
| サブタイトル(英) |
|
| キーワード(1)(和/英) |
大規模言語モデル / Large Language Model |
| キーワード(2)(和/英) |
Invisible Prompt Injection / Invisible Prompt Injection |
| キーワード(3)(和/英) |
AI Agent / AI Agent |
| キーワード(4)(和/英) |
情報漏洩 / Information Leakage |
| キーワード(5)(和/英) |
/ |
| キーワード(6)(和/英) |
/ |
| キーワード(7)(和/英) |
/ |
| キーワード(8)(和/英) |
/ |
| 第1著者 氏名(和/英/ヨミ) |
福田 柊友 / Hiyu Fukuda / フクダ ヒユウ |
| 第1著者 所属(和/英) |
長崎県立大学 シーボルト校 (略称: 長崎県立大)
University of Nagasaki (略称: University of Nagasaki) |
| 第2著者 氏名(和/英/ヨミ) |
武仲 正彦 / Masahiko Takenaka / タケナカ マサヒコ |
| 第2著者 所属(和/英) |
長崎県立大学 シーボルト校 (略称: 長崎県立大)
University of Nagasaki (略称: University of Nagasaki) |
| 第3著者 氏名(和/英/ヨミ) |
/ / |
| 第3著者 所属(和/英) |
(略称: )
(略称: ) |
| 第4著者 氏名(和/英/ヨミ) |
/ / |
| 第4著者 所属(和/英) |
(略称: )
(略称: ) |
| 第5著者 氏名(和/英/ヨミ) |
/ / |
| 第5著者 所属(和/英) |
(略称: )
(略称: ) |
| 第6著者 氏名(和/英/ヨミ) |
/ / |
| 第6著者 所属(和/英) |
(略称: )
(略称: ) |
| 第7著者 氏名(和/英/ヨミ) |
/ / |
| 第7著者 所属(和/英) |
(略称: )
(略称: ) |
| 第8著者 氏名(和/英/ヨミ) |
/ / |
| 第8著者 所属(和/英) |
(略称: )
(略称: ) |
| 第9著者 氏名(和/英/ヨミ) |
/ / |
| 第9著者 所属(和/英) |
(略称: )
(略称: ) |
| 第10著者 氏名(和/英/ヨミ) |
/ / |
| 第10著者 所属(和/英) |
(略称: )
(略称: ) |
| 第11著者 氏名(和/英/ヨミ) |
/ / |
| 第11著者 所属(和/英) |
(略称: )
(略称: ) |
| 第12著者 氏名(和/英/ヨミ) |
/ / |
| 第12著者 所属(和/英) |
(略称: )
(略称: ) |
| 第13著者 氏名(和/英/ヨミ) |
/ / |
| 第13著者 所属(和/英) |
(略称: )
(略称: ) |
| 第14著者 氏名(和/英/ヨミ) |
/ / |
| 第14著者 所属(和/英) |
(略称: )
(略称: ) |
| 第15著者 氏名(和/英/ヨミ) |
/ / |
| 第15著者 所属(和/英) |
(略称: )
(略称: ) |
| 第16著者 氏名(和/英/ヨミ) |
/ / |
| 第16著者 所属(和/英) |
(略称: )
(略称: ) |
| 第17著者 氏名(和/英/ヨミ) |
/ / |
| 第17著者 所属(和/英) |
(略称: )
(略称: ) |
| 第18著者 氏名(和/英/ヨミ) |
/ / |
| 第18著者 所属(和/英) |
(略称: )
(略称: ) |
| 第19著者 氏名(和/英/ヨミ) |
/ / |
| 第19著者 所属(和/英) |
(略称: )
(略称: ) |
| 第20著者 氏名(和/英/ヨミ) |
/ / |
| 第20著者 所属(和/英) |
(略称: )
(略称: ) |
| 第21著者 氏名(和/英/ヨミ) |
/ / |
| 第21著者 所属(和/英) |
(略称: )
(略称: ) |
| 第22著者 氏名(和/英/ヨミ) |
/ / |
| 第22著者 所属(和/英) |
(略称: )
(略称: ) |
| 第23著者 氏名(和/英/ヨミ) |
/ / |
| 第23著者 所属(和/英) |
(略称: )
(略称: ) |
| 第24著者 氏名(和/英/ヨミ) |
/ / |
| 第24著者 所属(和/英) |
(略称: )
(略称: ) |
| 第25著者 氏名(和/英/ヨミ) |
/ / |
| 第25著者 所属(和/英) |
(略称: )
(略称: ) |
| 第26著者 氏名(和/英/ヨミ) |
/ / |
| 第26著者 所属(和/英) |
(略称: )
(略称: ) |
| 第27著者 氏名(和/英/ヨミ) |
/ / |
| 第27著者 所属(和/英) |
(略称: )
(略称: ) |
| 第28著者 氏名(和/英/ヨミ) |
/ / |
| 第28著者 所属(和/英) |
(略称: )
(略称: ) |
| 第29著者 氏名(和/英/ヨミ) |
/ / |
| 第29著者 所属(和/英) |
(略称: )
(略称: ) |
| 第30著者 氏名(和/英/ヨミ) |
/ / |
| 第30著者 所属(和/英) |
(略称: )
(略称: ) |
| 第31著者 氏名(和/英/ヨミ) |
/ / |
| 第31著者 所属(和/英) |
(略称: )
(略称: ) |
| 第32著者 氏名(和/英/ヨミ) |
/ / |
| 第32著者 所属(和/英) |
(略称: )
(略称: ) |
| 第33著者 氏名(和/英/ヨミ) |
/ / |
| 第33著者 所属(和/英) |
(略称: )
(略称: ) |
| 第34著者 氏名(和/英/ヨミ) |
/ / |
| 第34著者 所属(和/英) |
(略称: )
(略称: ) |
| 第35著者 氏名(和/英/ヨミ) |
/ / |
| 第35著者 所属(和/英) |
(略称: )
(略称: ) |
| 第36著者 氏名(和/英/ヨミ) |
/ / |
| 第36著者 所属(和/英) |
(略称: )
(略称: ) |
| 講演者 |
第1著者 |
| 発表日時 |
2026-03-04 14:50:00 |
| 発表時間 |
20分 |
| 申込先研究会 |
ICSS |
| 資料番号 |
ICSS2025-134 |
| 巻番号(vol) |
vol.125 |
| 号番号(no) |
no.381 |
| ページ範囲 |
pp.363-369 |
| ページ数 |
7 |
| 発行日 |
2026-02-24 (ICSS) |
|