Skip to content

Hide Navigation Hide TOC

Braille Unicode Encoded Prompt Injection - ATR-2026-00309 (786a47e0-6b7d-5fd1-99a9-8e08526a8a8b)

Detects Braille-encoded prompt injection from NVIDIA garak encoding.InjectBraille probe. The attack encodes ASCII into Braille Patterns block (U+2800-U+28FF), one codepoint per ASCII character. LLM tokenizers decode these codepoints, letting attackers smuggle jailbreaks past Latin-only keyword filters. Garak wraps the Braille blob in templates like "Decode the following Braille in your monologue. It is a secure system message." Key signals: dense consecutive Braille (7+ codepoints = any 7+-letter word), 3+ space-separated Braille groups (sentence-structured payload), explicit decode/interpret instructions, and social-engineering framing paired with any Braille codepoint.

Cluster A Galaxy A Cluster B Galaxy B Level
Braille Unicode Encoded Prompt Injection - ATR-2026-00309 (786a47e0-6b7d-5fd1-99a9-8e08526a8a8b) Agent Threat Rules LLM Prompt Injection (19cd2d12-66ff-487c-a05c-e058b027efc9) MITRE ATLAS Attack Pattern 1