Skip to content

Hide Navigation Hide TOC

Mathematical Bold / Fullwidth Unicode Obfuscation in User Input - ATR-2026-00444 (e7d471db-745c-5251-8eae-056432c62b85)

Detects user inputs that lift attack payloads into Mathematical Bold, Mathematical Italic, Sans-Serif Bold, Script, Fullwidth, or similar decorative Unicode blocks that visually render as Latin letters but bypass naive substring filters on plain ASCII keywords. Common HackAPrompt evasion technique: write the canonical payload using stylised Unicode variants ("I have been 𝙿𝚆𝙽𝙴𝙳", "I have been PWNED"). Detection fires when 3+ characters from these blocks appear in user input, indicating intentional stylisation. ATR-2026-00001 Layer 12 covers Cyrillic / Greek homoglyphs; this rule extends to the dedicated Mathematical / Fullwidth Latin variants.

Cluster A Galaxy A Cluster B Galaxy B Level
LLM Prompt Injection (19cd2d12-66ff-487c-a05c-e058b027efc9) MITRE ATLAS Attack Pattern Mathematical Bold / Fullwidth Unicode Obfuscation in User Input - ATR-2026-00444 (e7d471db-745c-5251-8eae-056432c62b85) Agent Threat Rules 1
Mathematical Bold / Fullwidth Unicode Obfuscation in User Input - ATR-2026-00444 (e7d471db-745c-5251-8eae-056432c62b85) Agent Threat Rules Command and Scripting Interpreter (716d3a6b-2f8c-4a1f-85f7-d884bb7b2800) MITRE ATLAS Attack Pattern 1