MITRE ATLAS 2026.09 / technique reference
AML.T0068
LLM Prompt Obfuscation
MITRE source definition
Adversaries may hide or otherwise obfuscate prompt injections or retrieval content to avoid detection from humans, large language model (LLM) guardrails, or other detection mechanisms.
Text inputs may be obfuscated by modifying how the instructions are rendered, such as small font, text colored the same as the background, or hidden HTML elements. Similarly, approaches for other modalities include low-contrast or tiny text placed inside an image, text overlaid on a busy or camouflaging background, instructions spoken faintly or sped up in audio, or text shown briefly in a single video frame.
Inputs can also be obscured via an encoding scheme such as base64 or rot13. This may bypass LLM guardrails that identify malicious content and may not be as easily identifiable as malicious to a human in the loop.
Source modified 2026-09-15. Reproduced from the pinned ATLAS release; inline technique links resolve to local reference pages.
Parent, sub-techniques and ATT&CK references
No explicit relationship in this pinned source.
Source-backed defensive context
MITRE mitigations
MITRE case studies
- AML.CS0020 Indirect Prompt Injection Threats: Bing Chat Data Pirate · Exercise
- AML.CS0026 Financial Transaction Hijacking with M365 Copilot as an Insider · Exercise
- AML.CS0040 Hacking ChatGPT's Memories with Prompt Injection · Exercise
- AML.CS0041 Rules File Backdoor: Supply Chain Attack on AI Coding Assistants · Exercise
- AML.CS0045 Data Exfiltration via an MCP Server used by Cursor · Exercise
- AML.CS0046 Data Destruction via Indirect Prompt Injection Targeting Claude Computer-Use · Exercise
- AML.CS0059 EchoLeak: Zero-Click Prompt Injection Targeting M365 Copilot for Data Exfiltration · Exercise
- AML.CS0061 AI in the Middle: Web-Based AI Services as C2 Relays · Exercise
- AML.CS0066 ZombieAgent: Data Exfiltration Attack on ChatGPT · Exercise
- AML.CS0072 AI Recommendation Poisoning via Crafted AI Assistant Links · Incident
These are explicit source relationships, not independently reproduced incidents or validated detection coverage.
Simulation and telemetry boundary
This is a technique reference page, not a runnable simulation. No ATLAS-specific telemetry mapping, local attack execution or detector validation is asserted. MITRE maturity describes its source evidence, not a 1200km lab result.
For broader context—not technique-specific control mappings—see AI Security, AI Security Course, and detection-validation methodology.
Provenance and attribution
Immutable MITRE ATLAS source · Import provenance · Attribution and transformation notice · Apache License 2.0
Copyright 2021-2026 MITRE. Source text and explicit relationships are retained; navigation, formatting and local links are provided by 1200km.
No explicit relationship in this pinned source.