2 Sources
[1]
Gemini hackers can deliver more potent attacks with a helping hand from... Gemini
In the growing canon of AI security, the indirect prompt injection has emerged as the most powerful means for attackers to hack large language models such as OpenAI's GPT-3 and GPT-4 or Microsoft's Copilot. By exploiting a model's inability to distinguish between, on the one hand, developer-defined
[2]
Gemini hackers are using its own tools against it
Google says it's always working on defenses, but the researchers believe that fixing the issue may impact useful features for developers. They say it takes a thief to catch a thief, and perhaps the same is true when it comes to hacking LLMs. Academic researchers have discovered a way to make
Share
Copy Link
Academic researchers have developed a novel method called "Fun-Tuning" that leverages Gemini's own fine-tuning API to create more potent and successful prompt injection attacks against the AI model.

In a significant development in AI security, academic researchers have devised a new technique called "Fun-Tuning" that dramatically improves the effectiveness of prompt injection attacks against Google's Gemini AI models. This method exploits Gemini's own fine-tuning API, typically used for customizing the model for specific domains, to generate more potent attacks
1
.Prompt injection attacks have been a known vulnerability in large language models (LLMs) like GPT-3, GPT-4, and Microsoft's Copilot. However, the closed nature of these models, where the underlying code and training data are closely guarded, has made it challenging for attackers to devise effective injections without extensive trial and error
1
.The new "Fun-Tuning" method, developed by researchers from UC San Diego and the University of Wisconsin, uses an algorithmic approach to optimize prompt injections. It employs discrete optimization, a technique for efficiently finding solutions among numerous possibilities. The process involves:
1
The "Fun-Tuning" method has proven to be remarkably effective:
1
Related Stories
This discovery raises several concerns in the AI security landscape:
2
Google has acknowledged the issue and stated that they are continuously working on defenses. However, the researchers believe that addressing this vulnerability may impact useful features for developers who rely on the fine-tuning API
2
.As AI models become increasingly integrated into various applications and services, the discovery of such vulnerabilities underscores the ongoing challenges in balancing functionality with security in the rapidly evolving field of artificial intelligence.
Summarized by
Navi
[2]
30 Sept 2025•Technology

31 Jan 2025•Technology

30 Jul 2025•Technology
