Overview of VDA. A resume PDF is converted into two representations: a visual representation consisting of rendered page images (what a human would see), and a textual representation consisting of machine-extracted text (which may include hidden content). A vision-language model identifies text present in the extraction but absent from the rendered images. Any such hidden excerpts indicate that the resume contains injected content and is flagged as malicious. Credit: arXiv (2026). DOI: 10.48550/arxiv.2605.28999
In an increasingly competitive job market, some applicants are quietly trying to outsmart AI hiring tools. Now, new research focused on rooting out the practice of "prompt injection" shows how widespread this tactic is.
A large-scale analysis from Duke University and collaborators in academia and industry found that at least 1% of resumes submitted to a popular hiring platform contained hidden instructions designed to trick the AI systems that filter applicants. The trend is accelerating quickly, researchers note, as tutorials, templates and online videos spread.
The study, which will be presented at the USENIX Security Symposium in August, examined 200,000 real resumes submitted to the industry research collaborator hireEZ. It is the first systematic investigation of prompt injection in a widely used, real-world AI application. The work is also available on the arXiv preprint server.






