• Resumo

    Injeção Indireta de Prompt no Gemini

    Data de publicação: 09/06/2026

    This paper investigates the Indirect Prompt Injection vulnerability in Large Language Models (LLMs), focusing on the Gemini model integrated into Google Workspace. Classified as LLM01 by OWASP, this flaw occurs when the model processes malicious hidden instructions, confusing them with prompt commands. The methodology consisted of creating resumes containing hidden payloads via simple visual steganography (invisible text), submitted to Gemini analysis in a simulated recruitment scenario. The results demonstrated the compromise of the model's integrity in three distinct vectors: (i) manipulation of technical competence, (ii) evasion of geolocation filters, and (iii) masking of hyperlinks for phishing purposes. The study highlights that the architectural inability of current LLMs to distinguish instructions from data (the Inherently Confusable Deputy problem) represents a critical risk. It is concluded that the implicit trust in content processed by LLMs should be reevaluated, requiring new layers of security beyond traditional prompt engineering.

Anais do Computer on the Beach

O Computer on the Beach é um evento técnico-científico que visa reunir profissionais, pesquisadores e acadêmicos da área de Computação, a fim de discutir as tendências de pesquisa e mercado da computação em suas mais diversas áreas.

Access journal