What Is Visual Prompt Injection?
Visual prompt injection hides malicious instructions inside an image, formatted or colored to be imperceptible to a human viewer but fully readable by the model processing it, so a text prompt can look completely benign while the accompanying image carries the actual attack. This is no longer an edge case: multimodal AI systems that process images by default are standard now, and the same principle extends to AI agents that take screenshots or process visual input to navigate interfaces, meaning the range of places a visual injection could originate has grown well beyond a single uploaded image.
Why It Matters
- Human-Invisible: designed to evade visual review while remaining parseable by the model.
- No Longer an Edge Case: multimodal processing is now standard, not experimental.
- Expanding Surface: applies to screenshots and UI-navigating agents, not just uploaded images.