
What happened
A study presented at USENIX Security Symposium 2026 examined 196,682 resumes from hiring platforms and detected hidden attack text in 2,030 of them — about 1%, or roughly one in every 100 applications.
Why it matters
Because the hidden text is invisible to human reviewers, recruiters using AI resume screening may be scoring manipulated applications without knowing it, which could distort who gets shortlisted.
WHO IT HITSRecruiters and hiring teams that rely on AI resume screening tools are the most directly affected, since the hidden text is designed to be read by those systems and not by human reviewers. Job candidates competing against manipulated resumes may also see their odds shift.
Summaries like this, in your inbox every morning.
The study set out to test whether a long-theorized risk — candidates slipping instructions into resumes to steer AI screening — was actually happening in the real job market, rather than only in lab demonstrations. To do so, the team built a detection system and ran it against 196,682 resume records supplied by a hiring support platform, covering data from July 2019 to December 2025 and from July 2024 to November 2025.
What the detection system surfaced was not a rare curiosity but a recurring pattern: 2,030 resumes, about 1% of the total, carried concealed text. The concealment methods were low-tech — matching the background color or shrinking the font to near-invisibility — and the content skewed toward keyword stuffing, followed by fabricated work history and achievements, with some applicants simply pasting the job posting's requirements.
Because these tricks target the AI reader rather than the human one, the finding raises a practical question for employers that have moved resume review to automated systems: the same document can look clean to a recruiter and loaded to the model scoring it. The paper's detection approach, presented at USENIX Security Symposium 2026, suggests screening pipelines may need to inspect what is actually in the file, not just what appears on the page.
Pick your industry and the AI tools you use, and get news related to your work every day.
Free · 30 seconds with Google · unsubscribe anytimeWhat is AIToday? →
Ask AI anything about this article. The AI reads this article, earlier AIToday articles, and Wikipedia, and cites its sources. Q&As are published on this page for other readers too.
Stanford and Carnegie Mellon researchers tracked 1182 Character.AI users from September 2024 to August 2025, t…

Google Cloud announced Gemini Agent, a cloud-based multi-agent tool

Google Cloud announced Gemini agent, a universal agent that handles answers, knowledge work, media creation, a…

The guide shows code that pulls AAPL prices with yfinance, averages tweet sentiment via TextBlob, then fits a…

The open-source ax-engine for Apple Silicon Macs measured over 76 tok/s decode on one M5 Max setup, and about…

Anthropic's October 8, 2026 update adds a ban on sustained and unnecessary abusive or cruel behavior toward Cl…
