Why is it possible to have hidden text in a Word document? Why should the AI have access to that text?
As the sibling comments illustrate, “hidden text” isn’t well-defined, and it has legitimate purposes that end users consciously make use of. The AI needs access to it, for one because the user might actually want the AI to perform actions on the hidden text (not in the sense of following instructions stated in the hidden text, but in the sense of manipulating the hidden text as part of the document), and also because…
Document-borne AI worms can self-propagate through Copilot for Word
171–180 of 317 posts
Re: Document-borne AI worms can self-propagate through Copilot for Word
#172Re: Document-borne AI worms can self-propagate through Copilot for Word
#173Earlier quoted context omitted.
You're saying that people fall for phishing because scammers invent completely unrealistic scenarios that would never happen outside TV shows?
I am saying it is unbelievable scenario and yes, I want the person dealing with it ignore it as such.
• https://www.nbcnews.com/id/wbna12208992
• https://newsinfo.inquirer.net/1070007/suicidal-caller-mistak...
• https://hongkongfp.com/2026/04/15/woman-trapped-in-tai-po-bl...
• https://en.wikipedia.org/wiki/Triangle_Shirtwaist_Factory_fi...
Re: Document-borne AI worms can self-propagate through Copilot for Word
#174I may be naive here but can the hidden text not be flagged or outright removed before being passed to copilot? Why would there not be consideration for what a human user can see, especially if the hidden text was added by copilot in the first place?
Hide your prompt injection in terms & conditions, plain sight but totally invisible.
Re: Document-borne AI worms can self-propagate through Copilot for Word
#175Earlier quoted context omitted.
Only in systems that need to be themselves super generalist. Which is almost never the case.
LLMs are.
If the code/data separation can not be solved then the whole approach need to be scrapped.
Re: Document-borne AI worms can self-propagate through Copilot for Word
#176Earlier quoted context omitted.
Security minded programmers understand that. "People" as a whole have not even heard about mixing instructions and data, and certainly not the reasons why it is not a good idea. And AI chatbots are very much targeted at the second group, not the first.
> And AI chatbots are very much targeted at the second group, not the first. I suppose this is why the AI labs are famously not releasing developer-oriented tools.
Re: Document-borne AI worms can self-propagate through Copilot for Word
#177Earlier quoted context omitted.
I would wager the fact that it's not what your sentence says is why that is possible. The moment it gets actual "intelligence", it can figure out what's the question and what's the context; right now it's all just a magic jumbo mess. If any of this thing were "a generally intelligent system", the whole concept of "it has no idea what any of this is" would not be there.
Part of reading a document is that in the middle of it, it may ask the reader to do something. That is true for humans too. Sometimes they might not realize that the instructions are malicious or are coerced to comply. A simple example: Let’s say I know that you have a human assistant reading your email, summarizing and filtering it, and then forwarding on the important ones to you. I could write an email that is dir…
Re: Document-borne AI worms can self-propagate through Copilot for Word
#178> "At the time of publication, no robust mitigation for the broader vulnerability class is available" Isn't it obvious by now that it's never going to be possible to fix this kind of thing, at least until we stop mixing up instructions with data.
Re: Document-borne AI worms can self-propagate through Copilot for Word
#179Earlier quoted context omitted.
I would wager the fact that it's not what your sentence says is why that is possible. The moment it gets actual "intelligence", it can figure out what's the question and what's the context; right now it's all just a magic jumbo mess. If any of this thing were "a generally intelligent system", the whole concept of "it has no idea what any of this is" would not be there.
> The moment it gets actual "intelligence", it can figure out what's the question and what's the context; Humans fall for social engineering (“I know you are not allowed to give anybody that information without Id, but I’m your CEO, my phone and passport got stolen,…) I don’t see why AI should be different.
Re: Document-borne AI worms can self-propagate through Copilot for Word
#180Has anyone pointed out yet that in a world full of AIs, these worms are just memes? Memetic idea propagation, same as what happens with us apes.