Chattopadhyay and Ediga demonstrated attack targeting what AI doesn’t inspect during code review. Hidden instructions in PNG; delayed exfiltration disguised as legitimate code values.
Success varied by coding assistant wrapper, not underlying LLM. Same model behaved differently across platforms. Defensive recommendation: multimodal scrutiny of all non-code PR assets.