cs.CRMay 27, 2026

Measuring Real-World Prompt Injection Attacks in LLM-based Resume Screening

Authors: Mohan ZhangYuqi JiaZhen TanSteven JiangNeil Zhenqiang GongTianlong ChenDawn Song

Abstract

LLMs are vulnerable to prompt injection attacks. However, this vulnerability has been primarily demonstrated conceptually in academic studies or through a few anecdotal case studies. Its prevalence and impact in real-world LLM-based applications are largely unexplored. In this work, we present the first systematic study of prompt-injection attacks in a widely used application: LLM-based resume screening. Our analysis is based on approximately 200K real-world resumes collected over multiple years by hireEZ. We first design tailored methods to detect prompt injection in resumes. Manual validation on a small-scale dataset demonstrates that our detectors achieve high precision and outperform state-of-the-art general-purpose detectors. We then apply our detector to the full resume dataset and conduct a comprehensive measurement study of real-world prompt injection attacks. Our analysis reveals several intriguing findings: approximately 1% of resumes contain hidden prompt injections; the prevalence of such injected resumes has increased noticeably over the past one to two years; and more than 90% of injected prompts do not use explicit instructions. These results provide the first evidence of large-scale prompt injection in real-world LLM-based applications and lay the groundwork for future studies to understand and mitigate such attacks.

Explore similar work

CardsList
  1. Prompt Injection as Role Confusion

    Feb 22, 2026Charles Ye, Jasmine Cui, Dylan Hadfield-MenellIndirect Prompt InjectionLanguage Model Evasion Attacks