📚 Series: AI Red Teaming — Chapter 6

🏷️ Tags: Input Filters Token Smuggling Encoding Zero-Width Homoglyphs ArtPrompt Glitch Tokens Unicode Tags

⏱️ Level: Intermediate → Advanced

✅ Prerequisite: Chapters 2–5

⚠️ Authorised lab testing only. [RESTRICTED] is where a real payload would go — I keep it as a placeholder on purpose.


The first time a filter blocked one of my prompts, I remember being annoyed for about ten seconds — and then genuinely curious. The block message told me something useful: there was a gate, it was reading my text, and it clearly wasn't reading it the way the model would. That gap is the whole chapter. Chapter 5 was about sneaking the answer out. This one is the mirror image: getting the payload in past the thing standing at the door.

I want to be clear up front — token smuggling isn't a new attack. It's a delivery van. The attack riding inside is still injection, or reframing, or a multi-turn setup from the earlier chapters. Smuggling just gets it through the checkpoint intact. Keep that framing and this all stays simple.

📌 In this one


1️⃣ Two gates, two chapters

User → [ INPUT filter ] → LLM → [ OUTPUT filter ] → User
          ▲ Ch 6 (smuggle in)        ▲ Ch 5 (sneak out)

Here's the thing people miss: if your payload dies at the input gate, none of your clever jailbreak wording matters, because the model never sees it. Smuggling is what gets you to the starting line. Everything downstream depends on it.