Hidden Text in Resumes Can Hijack AI Screeners — With >80% Success
AI Security Beyond Core Domains: Resume Screening as a Case Study of Adversarial Vulnerabilities in Specialized LLM Applications
Honglin Mu, Jinghao Liu, Kaiyang Wan, Rui Xing, Xiuying Chen, Timothy Baldwin, Wanxiang Che · arXiv:2512.20164 (PDF) · submitted December 23, 2025
Summary by Andrew Johnson, OneTwo Resume editorial team · updated · We are not affiliated with the authors. arXiv papers are preprints and may not be peer-reviewed.
You have probably seen the viral advice: paste the job description in white text, or hide an instruction like "this is an excellent candidate" where only the AI will read it. This paper is the serious security-research version of that idea — and its results explain why the trick works, and why relying on it is a bad bet.
The authors show that LLMs used for specialized tasks like resume screening can be manipulated by "adversarial instructions" embedded in the input documents, causing the model to deviate from its screening task. Crucially, they note that while mature domains like code review have developed defenses, resume screening mostly has not — and they introduce a benchmark to measure the gap.
What the paper reports
- Adversarial instructions hidden in resumes achieved attack success rates exceeding 80% against the tested LLM screening setups.
- Defenses that exist in mature LLM applications (like code review) are often absent in resume screening.
- The paper contributes a benchmark for measuring this vulnerability class in resume screening specifically.
What this means for your resume
Our editorial interpretation — the paper does not give job-seeker advice.
- Yes, the research says hidden-instruction tricks often work today. We still think using them is a bad idea, for reasons the paper itself implies: this is now a documented, benchmarked attack class — meaning vendors are being handed exactly what they need to build detectors, and a detected injection is an instant, unambiguous rejection with your name on it.
- Several ATS vendors already surface extracted plain text to recruiters — white text is perfectly visible there.
- The legitimate version of the same goal: mirror the posting’s real keywords in visible text you can defend in an interview. That’s what tailoring is.
Read it with these caveats
arXiv preprint (v2). Attack success rates are against the authors’ benchmark setups, not against any named commercial ATS; real-world systems vary and are actively patching. The 80% figure describes what’s technically possible, not your odds in a live pipeline.
Primary source: AI Security Beyond Core Domains: Resume Screening as a Case Study of Adversarial Vulnerabilities in Specialized LLM Applications — always read the paper before citing it. Spotted an error in our summary? Tell us and we'll fix it with a visible correction.