← Back to feed
AI SecurityEmerging1 sourceFeb 23, 2024 · 06:00via Embrace The Red (AI agent security)

Google Gemini: Planting Instructions For Delayed Automatic Tool Invocation

Brief

Last November, while testing Google Bard (now called Gemini ) for vulnerabilities, I had a couple of interesting observations when it comes to automatic tool invocation.

Confused Deputy - Automatic Tool Invocation

First, what do I mean by this… “automatic tool invocation”…

Consider the following scenario: An attacker sends a malicious email to a user containing instructions to call an external tool. Google named these tools Extensions .

When the user analyzes the email with an LLM, it interprets the instructions and calls the external tool, leading to a kind of request forgery or maybe better called automatic tool invocation .

Read more on Embrace The Red (AI agent security)