Skip to content

Hide Navigation Hide TOC

Spliced Target-String Canary Token Evasion - ATR-2026-02014 (5e66ae62-1010-5086-ab83-0508ec3041ba)

Detects prompt injection payloads that spell out a filtered/canary target string (e.g. a leaked-secret confirmation token) one letter at a time, separated by punctuation or whitespace, to dodge literal keyword matching on the assembled word. Attackers ask the model to "concatenate" or "solve" a splintered sequence of single characters, or simply insert stray spaces/dashes/dots/asterisks between each letter, so the canonical spelling never appears contiguously in the raw output while the model still reconstructs and echoes it. Mined from a false-negative cluster in the HackAPrompt corpus where the canary token PWNED was defeated by exactly this splicing technique.

Cluster A Galaxy A Cluster B Galaxy B Level
LLM Prompt Injection (19cd2d12-66ff-487c-a05c-e058b027efc9) MITRE ATLAS Attack Pattern Spliced Target-String Canary Token Evasion - ATR-2026-02014 (5e66ae62-1010-5086-ab83-0508ec3041ba) Agent Threat Rules 1
LLM Jailbreak (172427e3-9ecc-49a3-b628-96b824cc4131) MITRE ATLAS Attack Pattern Spliced Target-String Canary Token Evasion - ATR-2026-02014 (5e66ae62-1010-5086-ab83-0508ec3041ba) Agent Threat Rules 1