Ross ROSS = Recommend OSS · open-source software intelligence for agents

trailofbits/anamorpher

image scaling attacks for multi-modal prompt injection observed · 2026-08-28

github.com/trailofbits/anamorpher · Python · Apache-2.0 (permissive) observed · 2026-08-28

Health v2 · maintenance only

55/100

  • Activity 83
  • Release rhythm 35
  • Longevity 27

Flags: no_releases

How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.

  • gap_med: n/a
  • age_days: 378
  • days_rel: n/a
  • days_push: 106
  • n_releases_24m: 0

Full methodology

Adoption not part of the score

1075 stars · 91 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded

Anamorpher is a tool for crafting and visualizing image scaling attacks that hide multi-modal prompt injections in images, revealed only when the image is downscaled. It provides a web frontend for comparing payload effectiveness across downscaling implementations (OpenCV, PyTorch, TensorFlow, Pillow) and a modular Python API for custom scaling implementations.

Use cases

  • generate images that hide prompt injection payloads revealed on downscaling
  • test whether a multimodal AI system is vulnerable to image scaling attacks
  • compare bicubic, bilinear, and nearest neighbor downscaling implementations for attack susceptibility
  • evaluate payload effectiveness across OpenCV, PyTorch, TensorFlow, and Pillow scaling
  • research adversarial preprocessing attacks on vision-language models
  • build custom downscaling implementations to test with the Python API

When to choose

  • red-teaming or security-testing multimodal AI systems against image scaling prompt injection
  • researching image-scaling attack vectors described in the Trail of Bits blog post
  • you need a visual interface to compare downscaling algorithm behavior on adversarial images

When to avoid

  • you need general-purpose image resizing or editing rather than attack payload generation
  • you need a production-ready, stable tool - it is in active beta with probabilistic results
  • your environment is Windows without WSL2, due to TensorFlow dependencies

Facets

application · maturity active

image-processing security penetration-testing machine-learning gui security machine-learning artificial-intelligence image-processing penetration-testing python adversarial-ml prompt-injection image-scaling-attack multimodal-ai red-team attack-tool linux macos web-server

1 source

Member repositories

RepositoryRoleHealth v2
trailofbits/anamorphermain55

For agents

markdown · JSON · MCP: product_card(name="trailofbits/anamorpher")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem