Black Hat Europe 2025 | Weaponizing Image Scaling Against Production AI Systems @BlackHatOfficialYT
Black Hat Europe 2025 | Weaponizing Image Scaling Against Production AI Systems  @BlackHatOfficialYT
Uploaded June 2026 | Updated September 2026, 3 weeks ago
AI vision systems see differently than humans do. When platforms downscale uploads to save compute, the mathematical properties of interpolation algorithms create exploitable artifacts. In this presentation, we'll show how to craft images which use invisible pixel perturbations to reveal malicious prompts after downscaling, triggering unauthorized tool execution across Google Gemini, Vertex AI, Google Assistant, and Genspark. Beyond image downscaling, we'll explore the broader attack surface, including audio transformations, dithering algorithms, and other preprocessing steps that become prompt injection vectors. You'll learn to fingerprint vulnerable systems using test patterns that reveal specific downscaling implementations across AI libraries. We'll demo Anamorpher, our open-source tool for automated attack generation, with both Python APIs and visual interfaces, as well as examine practical mitigations from displaying actual processed images to implementing design patterns resistant to prompt injection, such as the action selector pattern.

By:
Suha Hussain | AI Research Engineer, Product Security, Harvey
Kikimora Morozova | Security Researcher, Trail of Bits

blackhat.com/eu-25/briefings/schedule/?#weaponizing-image-scaling-against-production-ai-systems-49911
Black Hat Europe 2025 | Weaponizing Image Scaling Against Production AI SystemsBlack Hat Stories | Or Yair, Security Research Team Lead at SafeBreachBlack Hat Europe 2025 | Habemus Securitas - Exploring Apples Hidden TerritoriesAll Your Secrets Belong to Us: Leveraging Firmware Bugs to Break TEEsSecTor 2025 | Leading Across the GenerationsBlack Hat Asia 2026 | Exploiting DFIR Agents Through Adversarial ManipulationBlack Hat Asia 2026 | Subverting Screen Trust via State Disruption and ONE-WAY FloodingSecTor 2025 | Detecting Forbidden White Labeled and Counterfeit DevicesBlack Hat Europe 2025 | ORMageddon: Leaking More Than You Joined ForBlack Hat Europe 2025 | Ghost In The Stack: Evolving Call Stack Spoofing In A Post-CET EraSecTor 2025 | Security and Safety Testing for Agentic AIBlack Hat Intercepted Video Series | Lexie Thach
Black Hat |

Black Hat Europe 2025 | Weaponizing Image Scaling Against Production AI Systems

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER