Skip to main content
  • AI Security Academy

    AI Security Academy

    What is AI Security

    AI security is not a neat, one-line definition you can slap on a slide.

    AI Security Glossary

    Explore some of the most common terms in AI Security

    AI Usage Stats

    Explore current AI usage trends.

  • Tools

    AI Security Tools

    OneClaw

    Track and analyze OpenClaw deployments in your org

    ClawSec

    Secure your OpenClaw, NanoClaw, and Hermes agents.

    Prompt Fuzzer

    Get our AI vulnerability assessment open source tool

  • Blog
  • Startup Map
  • Learn More
    Book a Demo
  • AI Security Academy

    AI Security Academy

    What is AI Security

    AI security is not a neat, one-line definition you can slap on a slide.

    AI Security Glossary

    Explore some of the most common terms in AI Security

    AI Usage Stats

    Explore current AI usage trends.

  • Tools

    AI Security Tools

    OneClaw

    Track and analyze OpenClaw deployments in your org

    ClawSec

    Secure your OpenClaw, NanoClaw, and Hermes agents.

    Prompt Fuzzer

    Get our AI vulnerability assessment open source tool

  • Blog
  • Startup Map
  • Learn More
    Book a Demo
Skip to main Content
Back to Glossary

Visual Prompt Injection

What Is Visual Prompt Injection?

Visual prompt injection hides malicious instructions inside an image, formatted or colored to be imperceptible to a human viewer but fully readable by the model processing it, so a text prompt can look completely benign while the accompanying image carries the actual attack. This is no longer an edge case: multimodal AI systems that process images by default are standard now, and the same principle extends to AI agents that take screenshots or process visual input to navigate interfaces, meaning the range of places a visual injection could originate has grown well beyond a single uploaded image.

Why It Matters

  • Human-Invisible: designed to evade visual review while remaining parseable by the model.
  • No Longer an Edge Case: multimodal processing is now standard, not experimental.
  • Expanding Surface: applies to screenshots and UI-navigating agents, not just uploaded images.

‍

FAQ

Not reliably. That's the point of the technique, the instructions are specifically formatted or colored to be imperceptible to a human viewer while remaining fully readable by the model.

No. The same principle applies to any visual input a model processes, including screenshots taken by an AI agent navigating a user interface.


Share this page

Related Terms


Prompt Injection

Prompt injection is an attack where crafted input causes a large language model to deviate from its intended instructions and follow the attacker's instead.

Related Resources

Prompt Injection 101

AI Risks

Nov 3rd, 2024

Uncover real-world prompt injection examples and learn how these attacks work, why they’re hard to block & what you can do to protect AI systems.

Log In
Learn More
Book a Demo

Resources

Blog
AI Security Glossary
What is AI Security?
PromptCast: The Voice of AI & Security
ClawSec
OneClaw
Prompt Fuzzer
AI Security Startup Map
© {{year}} Prompt Security. All Rights Reserved.
Privacy Policy
Terms of Service

Follow Us