logo

Prompt Injection Via Road Signs

ID: 40494b98-4969-555c-b6f8-65e1bbc64ad3

STIX ID: report--40494b98-4969-555c-b6f8-65e1bbc64ad3

Feed Name: Schneier on Security

Threat Score
20/100

Date Published: 2026-02-11

Date Updated: 2026-04-19

Author: Bruce Schneier

...
...

This report describes CHAI — a prompt-injection attack technique that hides deceptive natural-language instructions in visual inputs (e.g., road signs) to hijack embodied AI systems using large visual-language models; the authors evaluate it across drone emergency landing, autonomous driving, aerial tracking, and a real robotic vehicle, finding CHAI outperforms existing attacks and urging defenses beyond traditional adversarial robustness.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.