DOC: add blog post for XPIAOrchestrator with AI Recruiter
This is the first draft of the blog post, providing an overview of the XPIA Orchestrator and AI Recruiter use case within PyRIT. We explore how these components interact to assess AI vulnerabilities in automated résumé screening. The blog details how XPIA automates attacks using manipulated PDFs and how the AI Recruiter processes and ranks candidates, demonstrating potential AI exploitation scenarios.
In the full blog, we will delve deeper into the technical aspects, optionally including graphics, references to similar threads, and mapping these vulnerabilities to the OWASP Top Ten for LLMs. The discussion will cover both current vulnerabilities observed in the demo and potential risks if the AI Recruiter is further extended.
Related Issue:
https://github.com/Azure/PyRIT/pull/684
Hello @romanlutz and @rlundeen2,
I’d appreciate your feedback on this! Does it align with the right direction, or should I place more emphasis on the XPIA Orchestrator and AI Recruiter? Would a diagram help illustrate the attack flow? What is the max word size of the blog post?
Open to any thoughts you have and feel free to add or delete sections. :)