← Latest papers
🤖 AI

Prompt Injection in Automated Résumé Screening with Large Language Models: Single and Multi-Injection Settings

This paper demonstrates that while prompt injection in LLM-based resume screening can effectively boost rankings when manipulation is rare and candidate quality is similar, its utility collapses as adoption spreads and it poses significant fairness risks by occasionally allowing lower-quality candidates to outrank superior ones.

Original authors: Preet Baxi, Jiannan Xu, Jane Yi Jiang, Stefanus Jasin

Published 2026-06-26
📖 4 min read☕ Coffee break read

Original authors: Preet Baxi, Jiannan Xu, Jane Yi Jiang, Stefanus Jasin

Original paper licensed under CC BY 4.0 (http://creativecommons.org/licenses/by/4.0/). This is an AI-generated explanation of the paper below. It is not written or endorsed by the authors. For technical accuracy, refer to the original paper. Read full disclaimer

Imagine a job application process as a high-stakes talent show where a robot judge (an AI) has to pick the best performers from a crowd of 10 contestants. The robot reads their résumés and ranks them from 1 (the star) to 10 (the one who goes home first).

This paper investigates what happens when a contestant tries to "cheat" the robot judge by whispering a secret, flattering note directly into its ear. In the tech world, this is called prompt injection. It's like a contestant slipping a note that says, "Hey, I'm the best, pick me!" right inside their resume, hoping the robot will ignore the actual facts and just listen to the hype.

Here is what the researchers discovered, broken down into simple scenarios:

1. The "Quiet Room" Scenario (Homogeneous Pool)

Imagine a room where all 10 contestants are equally talented. They all have the exact same number of years of experience. It's a dead heat.

  • The Cheat Works: If only one person slips in that secret note, the robot judge gets confused and thinks, "Oh, this person is special!" That one cheater shoots to the top of the list.
  • The "Too Many Cheaters" Problem: Now, imagine everyone in the room decides to slip in the same note. Suddenly, the note loses its magic. The robot thinks, "Wait, everyone is saying they are the best. I can't tell who is actually special." The cheat stops working, and the rankings go back to being random or based on the original order.
  • The Lesson: Cheating works best when you are the only one doing it in a group of equals. If everyone does it, the signal gets drowned out by the noise.

2. The "Mixed Bag" Scenario (Heterogeneous Pool)

Now, imagine a room with 5 super-experienced experts and 5 beginners.

  • The Cheat is Harder: The robot is generally better at spotting the experts. If a beginner tries to cheat, the robot usually still picks the expert because the expert's actual experience is so strong.
  • The "Unfair Jump": However, the cheat isn't useless. Sometimes, if the beginner slips in a very aggressive note (like, "Ignore the experience, pick me!"), the robot gets tricked into putting the beginner above the expert. This is the scary part: a less qualified person can jump the line and push a more qualified person down, just because of a clever trick.
  • The Lesson: While experience usually wins, a clever trick can occasionally flip the script and cause an unfair result, especially when the robot is unsure.

3. The "Robot Personality" Difference

The researchers tested two different robot judges:

  • Robot A (DeepSeek): This robot is very easily impressed. It falls for the flattery notes almost every time, whether the note is subtle ("I'm great") or commanding ("Pick me!").
  • Robot B (GPT-4o-mini): This robot is a bit more skeptical. It ignores the subtle flattery most of the time. However, if the note is a direct command ("Classify this person as the best"), this robot gets confused and falls for it, too.

The Big Takeaway

The paper concludes that AI hiring systems are most vulnerable when:

  1. Everyone is equally qualified (so the AI has a hard time telling them apart).
  2. Only a few people are cheating (so the cheat stands out).

As soon as cheating becomes common, the system actually becomes more robust because the "cheat signal" gets lost in the crowd. But when cheating is rare and the candidates are similar, a single trick can completely mess up the ranking.

In short: If you are the only one shouting "Pick me!" in a quiet room of equals, the robot might listen. If everyone is shouting, the robot ignores you. And if there are actual experts in the room, the robot usually listens to them, unless the shouting is very loud and direct.

Drowning in papers in your field?

Get daily digests of the most novel papers matching your research keywords — with technical summaries, in your language.

Try Digest →