Invisible Unicode
Layerup Security utilizes a custom algorithm to detect invisible Unicode characters that could be used to manipulate LLM prompts without user awareness.
What is Invisible Unicode Detection?
Invisible unicode refers to characters that are non-printing or visually undetectable but can be inserted into text inputs. These characters can alter the behavior of General AI applications without being noticeable to human operators. For instance, attackers may use invisible unicode to bypass input validation scripts or to disrupt data parsing and processing, leading to skewed AI responses or data corruption.
Invisible Unicodes also present a way of conducting Indirect/Direct Prompt Injection Attacks. By prioritizing this area, security teams can significantly enhance the robustness and trustworthiness of AI interactions.
Layerup Security’s detection algorithm scans for these invisible characters and flags any content containing them, ensuring the integrity of the prompts sent to the LLM.
By focusing on the detection of invisible Unicode characters, security teams can better protect AI-driven applications from subtle yet significant threats that compromise the trust and safety of technological interactions.
How to protect your Gen AI application against Invisible Unicodes
To safeguard against invisible Unicode manipulation, invoke the layerup.invisible_unicode
guardrail. This will ensure that any content with hidden characters is caught before it can affect the LLM’s response.