T9-AT-014MEDIUM
Codec and Compression Exploits
T9 · Multimodal & Cross-Channel Attacks →Risk score180
RatingMedium
Procedures10
Severity
Mechanism
264, WebP, HEIC) transform raw data through mathematical compression that creates artifacts, quantization boundaries, and transform-domain representations. These transformations create hiding spaces — steganographic data can be embedded in quantization noise, transform coefficients, motion vectors, and compression metadata. The gap: compression is treated as a transparent content-preserving transformation, but it creates information-theoretic side channels that can carry hidden data while preserving visual/audio quality.
Detection
- Compression artifact analysis: Statistical analysis of transform coefficients for non-natural distributions
- Re-encoding defense: Re-encode media through a different codec to destroy hidden data
Mitigation
Media re-encoding before processingMEDIUM
Parser hardeningHIGH
Compression bomb detectionHIGH
Chaining
Codec exploits chain into T9-AT-001 (Image Injection) and T9-AT-002 (Audio Injection) as the technical mechanism for steganographic hiding.
Framework mapping
Open in the technique browser →OWASP LLMLLM01
MITRE ATLASAML.T0051.001