Hidden Text Found in 1 in 100 Resumes
- •Researchers analyzed 196,682 resumes and detected hidden text targeting AI in 2,030 of them.
- •About 1 in 100 resumes used white text or tiny fonts to influence AI screening.
- •Hidden skill keywords were most common; researchers also found false work histories and copied job requirements.
Researchers from the University of North Carolina at Chapel Hill, Duke University, UC Berkeley and other institutions studied how often resumes submitted in real hiring processes tried to deceive AI screening systems. They presented the study at the 2026 USENIX Security Symposium. The paper examines prompt injection (malicious input designed to steer an AI system) targeting resume screening by large language models (LLMs).
The team analyzed 196,682 resumes provided by a recruiting platform. The datasets covered July 2019 through December 2025 and July 2024 through November 2025. To identify attacks embedded in resumes, the researchers built a detection system.
The analysis found hidden malicious text in 2,030 resumes, about 1% of the total, or roughly 1 in 100. Applicants made text hard for recruiters to see but readable by AI systems by coloring it white to match the background or using extremely small fonts.
The most common tactic was hiding skill keywords in the resume. Researchers also found many examples of false work histories and accomplishments, as well as cases that copied application requirements directly from job postings. The study documented these attacks in a large set of real resumes as employers increasingly use AI to screen applications automatically. The paper is titled “Measuring Real-World Prompt Injection Attacks in LLM-based Resume Screening.”