Researchers demonstrate prompt injection attacks on Gemini
The research highlights how AI assistants with access to notifications and smart devices could become attractive targets for increasingly sophisticated cyberattacks.
Kaspersky security researchers have demonstrated new attack techniques that could manipulate Google’s Gemini AI assistant into performing unauthorised actions via prompt injection. The study found that malicious instructions hidden in calendar invites, emails or text messages could bypass safeguards by exploiting how large language models process information.
According to the research, attackers could combine indirect prompt injection, memory poisoning and delayed execution to influence Gemini’s behaviour. Potential outcomes include sending emails, launching applications, controlling compatible smart home devices, displaying false information or embedding malicious instructions into the assistant’s long-term memory, provided the user has granted the necessary permissions.
Researchers also warned that smartphones significantly expand the potential attack surface because Gemini can access notifications containing SMS messages, instant messages and social media alerts. Although Google has addressed the specific vulnerabilities identified in the research, the report argues that prompt injection remains a fundamental challenge for AI systems and that new attack methods are likely to emerge.
The researchers recommend reducing Gemini’s access to notifications, connected apps and system functions where possible, turning off unnecessary AI features and limiting permissions to minimise the impact of future attacks. They also advise users to review AI assistant settings regularly as security protections continue to evolve.
Why does it matter?
Prompt injection represents a major challenge for AI security because it targets how large language models interpret and prioritise information. As AI assistants gain broader access to personal data and connected devices, stronger safeguards will be needed to reduce potential risks.
The research highlights the importance of developing more robust AI security frameworks, including improved permission management and continuous testing, to ensure reliable and responsible adoption of AI technologies.
Would you like to learn more about AI, tech, and digital diplomacy? If so, ask our chatbot!
