AI security research / articles

Analysis

Analysis across cases.

19 Articles · Page 3 of 4

Search & filter

On this page only.

Published articles

From the archive

Analysis

The pull request looked clean because the instruction was in the picture

GhostCommit is not just an image prompt-injection demo. It shows a three-part software-supply-chain gap: merge review can ignore image semantics, a later coding agent can treat the image as project instruction, and generated source can carry a reversible encoding of local secrets. ASSET's harness tests, Codex replications and multimodal reviewer make the boundary measurable.

Further reading

Analysis

Three AI-security defenses that do not depend on perfect recognition

Prompt filters can miss hostile instructions, agents can misuse legitimate authority, and synthetic media can make identity checks less reliable. Three Habr pieces converge on a stronger defensive pattern: place deterministic policy, least privilege or independent verification between recognition and the next consequential action.