New hack uses prompt injection to corrupt Gemini's long-term memory
arstechnica.com
arstechnica.com
...
> Another measure chatbot developers employ is a limitation on broad types of instructions that can be invoked by untrusted data. In Google’s case, this measure seems to include the invocation of apps or data available through its Workspace collaboration suite. (Google doesn’t document these restrictions anywhere, so researchers are left to infer them based on the behavior they observe.)
I understand the impetus to protect one's "special sauce" recipes in this nascent industry, but it sounds like it would be beneficial to everyone if they did more to document the protection mechanisms they are developing, and welcome outside review, if not contribution. I'm in no way an expert in AI or security, just picked up on a recurring theme, and wondered if anyone was working in this space, or knew of any specific efforts to establish some kind of standards of practice for AI security?