AltaySec · ATLAS 2026.07
AML.T0067

LLM Trusted Output Components Manipulation

C · Explainer (cannot be honestly simulated in-browser) AML.TA0007 · Defense Evasion

Description

Adversaries may utilize prompts to a large language model (LLM) which manipulate various components of its response in order to make it appear trustworthy to the user. This helps the adversary continue to operate in the victim's environment and evade detection by the users it interacts with. The LLM may be instructed to tailor its language to appear more trustworthy to the user or attempt to manipulate the user to take certain actions. Other response components that could be manipulated include links, recommended follow-up actions, retrieved document metadata, and Citations.

Honesty-tier rationale

This technique should be measured against a real defense stack; in-browser, only a simple filter-vs-filter illustration is honest.

Sub-techniques

Source

← Back to the matrix