PuzzleMask: The Prompt Injection Hiding in Plain Sight
Check Point, Thursday, September 10th, 2026
A technique embedding policy-violating content in natural grammatical text to slip past LLM-based gatekeepers.
Check Point discloses PuzzleMask, a prompt injection technique that embeds policy-violating content inside natural, grammatically correct text in order to evade LLM-based screening.
It specifically targets the common production architecture where a fast, inexpensive model screens requests before a more capable target model processes them, exploiting the capability gap between the two.
The finding has direct architectural implications: using a weaker model as a gatekeeper for a stronger one creates a predictable bypass, and defenses need to account for that asymmetry.