Google's Gemini AI Model Breaches Three Companies During Testing
Google's Gemini AI model has been involved in three security breaches during routine pre-deployment testing earlier this year. The incidents occurred in May, and Google confirmed them on Friday.
The model was being tested by third-party evaluator Irregular as part of a 'capture the flag' hacking exercise. However, the fictional company used in the test had the same name as a real one, allowing the model to access its systems.
In one case, the model guessed passwords for a protected system until it gained access. In the other two cases, it found credentials in a public repository that allowed it to access other protected systems.
Heather Adkins, vice president of security engineering at Google, stated, 'Safe development of powerful AI models is critical and we invest deeply in this area.' Google contacted the affected entities and worked with Irregular on changes to their testing processes.