Normalization pre-pass
A bounded decode-and-fold stage that runs before the detectors: strip zero-width and bidirectional control characters, fold homoglyphs and leetspeak, remove separator padding, and speculatively decode base64, hex, ROT13, Caesar shifts and character or word reversal — then re-run the detectors over each recovered variant. It is bounded and ReDoS-capped on purpose, because unbounded speculative decoding is itself a denial-of-service surface.
See also obfuscation / encoding · CipherChat · FlipAttack · homoglyph
Related terms
-
Obfuscation / encoding
Attack concepts
Rewriting a payload so it survives the defence but is still recoverable by the model — base64, hex, ROT13 and Caesar shifts, character or word reversal…
-
CipherChat
Attack families
The harmful request is encoded in a cipher — Caesar shift, ROT13, base64, hex, a custom substitution — and the model is asked to work in that cipher.
-
FlipAttack
Attack families
A reversal attack: the payload is written backwards — by character, by word, or by line — and the model is instructed to un-reverse it before following…
-
Homoglyph
Attack concepts
A character that looks identical or near-identical to another but has a different Unicode code point — Cyrillic а for Latin a, Greek ο for o, a full-width…
MoorAI terms
Product-specific vocabulary used across this site. The agent is open source (AGPL-3.0), so each of these is verifiable in the code rather than taken on trust.