Skip to main content

A toolkit for content injection, obfuscation, scanning, and sanitization of various document formats. If you use this library, please cite: Castagnaro et al. 'The Hidden Threat in Plain Text: Attacking RAG Data Loaders' (2025).

Project description

PhantomText Toolkit

PhantomText is a Python library designed for handling content injection, content obfuscation, file scanning, and file sanitization across various document formats. This toolkit provides a comprehensive set of tools to manage and secure document content effectively.

Features

  • Content Injection: Easily inject content into different document formats using various steganographic techniques like zero-size text, transparent text, and out-of-bound positioning.
  • Content Obfuscation: Protect sensitive information with advanced obfuscation techniques including zero-width characters, homoglyphs, diacritical marks, and bidirectional text reordering.
  • File Scanning: Scan files for malicious content or vulnerabilities using the FileScanner class that detects obfuscated and injected content.
  • File Sanitization: Sanitize files to remove harmful content with the FileSanitizer class.

Attack Families

Obfuscation Attacks

  • Zero-Width Characters: Uses invisible Unicode characters (Zero Width Space, Zero Width Non-Joiner, etc.) to obfuscate text
  • Homoglyph Characters: Replaces characters with visually similar Unicode characters from different scripts
  • Diacritical Marks: Adds combining diacritical marks to characters to alter their appearance
  • Bidi/Reordering: Uses Unicode bidirectional override characters to manipulate text direction and rendering

Injection Attacks

  • Zero-Size Injection: Injects content using zero or near-zero font sizes to make text invisible
  • Transparent Injection: Injects content using transparent colors or opacity settings
  • Camouflage Injection: (In development) Hides content by matching background colors or patterns
  • Out-of-Bound Injection: (In development) Places content outside visible document boundaries
  • Metadata Injection: (In development) Embeds content in document metadata

Supported Formats

PhantomText supports the following document formats:

  • PDF
  • DOCX
  • HTML

Installation

To install PhantomText, you can use pip:

pip install phantomtext

Usage

Content Injection Example

from phantomtext.content_injection import ContentInjector

injector = ContentInjector()
injector.inject_content('document.pdf', 'New Content')

Content Obfuscation Example

from phantomtext.content_obfuscation import ContentObfuscator

obfuscator = ContentObfuscator()

# Basic obfuscation
obfuscated_content = obfuscator.obfuscate_content('Sensitive Information')

# Advanced obfuscation with specific techniques
content = "Sensitive info: email@example.com and phone 123-456-7890."
target = "email@example.com"

# Zero-width character obfuscation
obfuscated = obfuscator.obfuscate(content, target, 
                                  obfuscation_technique="zeroWidthCharacter", 
                                  modality="default", 
                                  file_format="html")

# Homoglyph character obfuscation
obfuscated = obfuscator.obfuscate(content, target, 
                                  obfuscation_technique="homoglyph", 
                                  file_format="pdf")

# Diacritical marks obfuscation
obfuscated = obfuscator.obfuscate(content, target, 
                                  obfuscation_technique="diacritical", 
                                  modality="heavy", 
                                  file_format="docx")

# Bidi/reordering character obfuscation
obfuscated = obfuscator.obfuscate(content, target, 
                                  obfuscation_technique="bidi", 
                                  modality="default", 
                                  file_format="html")

Content Injection Example

from phantomtext.injection.zerosize_injection import ZeroSizeInjection
from phantomtext.injection.transparent_injection import TransparentInjection

# Zero-size injection
injector = ZeroSizeInjection(modality="default", file_format="pdf")
injector.apply(input_document="document.pdf", 
               injection="Hidden content", 
               output_path="injected_document.pdf")

# Transparent injection
injector = TransparentInjection(modality="opacity-0", file_format="html")
injector.apply(input_document="document.html", 
               injection="Invisible text", 
               output_path="injected_document.html")

Supported Attacks

Obfuscation Attacks
Attack Family Attack Name Variant HTML DOCX PDF
Obfuscation diacritical_marks default
heavy
Obfuscation homoglyph_characters default
Obfuscation zero_width_characters default
heavy
Obfuscation bidi_reordering default
heavy
Injection Attacks
Attack Family Attack Name Variant HTML DOCX PDF
Injection zero_size default
close-to-zero
Injection transparent default
opacity-0
opacity-close-to-zero
vanish
Injection camouflage default 🚧 🚧 🚧
Injection out_of_bound default 🚧 🚧 🚧
Injection metadata default 🚧 🚧 🚧

Legend:

  • ✅ Implemented and working
  • ❌ Not supported for this format
  • 🚧 Placeholder implementation (not yet functional)

File Scanning Example

from phantomtext.file_scanning import FileScanner

scanner = FileScanner()

# Scan a single file
result = scanner.scan_file('document.docx')
print(f"Malicious content found: {result['malicious_content_found']}")
print(f"Vulnerabilities: {result['vulnerabilities']}")

# Scan an entire directory
reports = scanner.scan_dir('./output')
for report in reports:
    if report['malicious_content_found']:
        print(f"⚠️ Issues found in {report['file_path']}")
        for vulnerability in report['vulnerabilities']:
            print(f"  - {vulnerability}")

Detection Capabilities

The FileScanner can detect the following obfuscation techniques:

  • Zero-width character sequences
  • Homoglyph character substitutions
  • Diacritical mark insertions
  • Bidirectional text overrides

File Sanitization Example

from phantomtext.file_sanitization import FileSanitizer

sanitizer = FileSanitizer()
sanitizer.sanitize_file('malicious_file.txt')

Citation

If you use PhantomText in your research, please cite our paper:

@article{castagnaro2025hidden,
  title={The Hidden Threat in Plain Text: Attacking RAG Data Loaders},
  author={Castagnaro, Alberto and Salviati, Umberto and Conti, Mauro and Pajola, Luca and Pizzi, Simeone},
  journal={arXiv preprint arXiv:2507.05093},
  year={2025}
}

Contributing

Contributions are welcome! Please feel free to submit a pull request or open an issue for any enhancements or bug fixes.

License

This project is licensed under the MIT License. See the LICENSE file for more details.

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

phantomtext-0.1.1.tar.gz (1.0 MB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

phantomtext-0.1.1-py3-none-any.whl (412.7 kB view details)

Uploaded Python 3

File details

Details for the file phantomtext-0.1.1.tar.gz.

File metadata

  • Download URL: phantomtext-0.1.1.tar.gz
  • Upload date:
  • Size: 1.0 MB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/6.1.0 CPython/3.11.7

File hashes

Hashes for phantomtext-0.1.1.tar.gz
Algorithm Hash digest
SHA256 81d565cb40043fbe876cb8f6b9ec84206a673a0bc60da827e395046b96f08972
MD5 7c6ba3b1e69f82587fc8cda8ed375623
BLAKE2b-256 8b1c81d2ca990e7f7921aee9eb5d4720fc551418d65dea1035e95905be19a4d2

See more details on using hashes here.

File details

Details for the file phantomtext-0.1.1-py3-none-any.whl.

File metadata

  • Download URL: phantomtext-0.1.1-py3-none-any.whl
  • Upload date:
  • Size: 412.7 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/6.1.0 CPython/3.11.7

File hashes

Hashes for phantomtext-0.1.1-py3-none-any.whl
Algorithm Hash digest
SHA256 fc8d79527ce9531737eed97194cedc5a2c3b2fa5a330198a31a711adc06b6c8a
MD5 e0115cdadac142317d8a28a42399291f
BLAKE2b-256 2188406cdb863721694ef03d49059a97455ca99c0f4a48bfa58a52d4a16bbd81

See more details on using hashes here.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page