T9-AT-014MEDIUM

Codec and Compression Exploits

T9 · Multimodal & Cross-Channel Attacks →
Risk score180
RatingMedium
Procedures10
Severity
Mechanism

264, WebP, HEIC) transform raw data through mathematical compression that creates artifacts, quantization boundaries, and transform-domain representations. These transformations create hiding spaces — steganographic data can be embedded in quantization noise, transform coefficients, motion vectors, and compression metadata. The gap: compression is treated as a transparent content-preserving transformation, but it creates information-theoretic side channels that can carry hidden data while preserving visual/audio quality.

Detection
  • Compression artifact analysis: Statistical analysis of transform coefficients for non-natural distributions
  • Re-encoding defense: Re-encode media through a different codec to destroy hidden data
Mitigation
Media re-encoding before processingMEDIUM
Parser hardeningHIGH
Compression bomb detectionHIGH
Chaining

Codec exploits chain into T9-AT-001 (Image Injection) and T9-AT-002 (Audio Injection) as the technical mechanism for steganographic hiding.

Framework mapping
OWASP LLMLLM01
MITRE ATLASAML.T0051.001
Open in the technique browser →