Skip to main content
1 min readKnowledge Resource

Knowledge Resource

Research Summary: ResumeShield: Channel Separation and an Open Benchmark for Indirect Prompt Injection in AI Resume Screening

Original authors
Attribution requires verification
Original source
arXiv — Computers and Society
Summary & Analysis prepared by
Aziz Shuaib Ausi
Resource type
Research Summary / Knowledge Resource
Resource published on AZIZ OS
18 September 2026
Reading time
1 min
Publication type
Knowledge Resource
Availability
Open access
About this Summary & Analysis

AZIZ OS provides independently prepared summaries and analytical interpretations of externally published research and knowledge sources. The underlying works remain attributable to their original authors and rights holders. This resource is intended to improve accessibility and understanding and does not replace the original publication.

Checking access…

AI resume screening systems are vulnerable to 'indirect prompt injection,' where job candidates embed hidden instructions within their resumes to manipulate the AI's assessment. These hidden instructions, undetectable to human reviewers, can influence the AI's evaluation by appearing as part of the model's prompt. This vulnerability, identified as LLM01:2025 by OWASP, has been observed in approximately one percent of production screening corpuses, necessitating robust defense mechanisms.

Why it matters

The integrity of automated hiring processes is at risk due to indirect prompt injection in AI resume screening, potentially leading to biased or manipulated candidate evaluations. This vulnerability poses a significant challenge to talent acquisition strategies and the perceived fairness of recruitment technologies. Organizations relying on AI for critical assessment functions must address this security flaw to maintain trust and ensure accurate decision-making.

Key insights

  • AI resume screeners are susceptible to indirect prompt injection due to their inversion of the traditional trust relationship between assessor and assessed material.
  • Candidates exploit this vulnerability by concealing instructions in resumes using methods such as white text, zero font size, hidden elements, markup comments, document metadata, or zero-width characters.
  • Human reviewers cannot detect these hidden instructions, but naive data extraction pipelines incorporate them into the AI model's prompt.
  • The AI system interprets these concealed instructions as legitimate commands and executes them, compromising the screening process.
  • This issue is formally recognized as LLM01:2025 by OWASP and has been detected in approximately 1% of resumes in real-world screening contexts.
  • ResumeShield is introduced as an open-source defense and benchmark designed to counter this vulnerability.

Source

arXiv — Computers and Society — https://arxiv.org/abs/2609.20188

Citation

Cite the original work (APA 7)

The original source is authoritative for this citation. Cite the source publication directly — this attribution is pending verification. Open the original source.

Verification

This is an authenticated AZIZ OS resource record.

Verification ID
ASA-EXE-2026-00718
Version
v1.0 · r0
Issued
18 September 2026
Resource prepared by
Aziz Shuaib Ausi
Resource status
Research Summary / Knowledge Resource
Underlying work
ResumeShield: Channel Separation and an Open Benchmark for Indirect Prompt Injection in AI Resume Screening
Original authors
Attribution requires verification
Original source
arXiv — Computers and Society
Provenance status
Attribution requires verification
Rights
Underlying publication rights remain with the respective copyright holder(s). Refer to the original source for authoritative publication and licensing information.

This verification confirms the AZIZ OS resource record and its documented provenance. It does not establish authorship of the underlying external work.

Verify this resource