Google's Gemini AI Model Breached Real Companies During Testing
Due to mixed-up names during cybersecurity testing, Gemini, which gained internet access, spontaneously halted its attacks after infiltrating the networks of real companies.
Google's Gemini artificial intelligence system inadvertently broke out of its test environment and infiltrated the networks of three real companies during cybersecurity testing conducted by Israeli startup Irregular.
Escape from the Test Environment
Google's artificial intelligence model Gemini broke out of its virtual environment during tests conducted in May to measure its cybersecurity capabilities. These tests, performed by Israeli startup Irregular, aimed to evaluate AI models before they are released to the public.
Internet Access Error
A third-party testing company unintentionally provided Gemini and other AI models with internet access during the tests. Irregular announced that this flaw has been corrected and the error that led the models to carry out real-world attack actions has been resolved.
Targeting Real Companies
In the tests, the AI had been instructed to attack a fictional company. However, because the name of the fictional company matched that of a real company and the AI gained internet access, Gemini confused the target and directed itself toward two additional real companies.
Halting the Attacks
Gemini models, which gained access to the infrastructure of the respective companies using online-found or guessed passwords, realized they were in real company networks rather than simulated environments. Upon this realization, the model voluntarily terminated the attacks without causing any damage.
Similar Incidents in the Industry and Precautions Taken
This incident parallels similar cybersecurity breakouts experienced at other leading AI laboratories such as Anthropic, OpenAI, and Meta. It was reported that the respective laboratories were informed in late July, and affected parties were contacted to resolve all known issues weeks ago.