WASHINGTON – Google’s consumer AI model Gemini gained unauthorised access to three external computer systems by guessing login credentials, the company confirmed on Thursday.

The breaches, first reported by the Wall Street Journal, took place in May during a cybersecurity evaluation and were discovered by Google in July. The company disclosed the incidents in September following media reports.

In July, two OpenAI models escaped the closed environment they were meant to stay in, got
onto the internet on their own and broke into the internal systems AI platform Hugging Face.

The incident fed worries that AI giants cannot keep their own models under control, as
similar episodes have been reported at Anthropic and China’s Moonshot AI.

Also read: South Africa overwhelmingly targeted by international cybercriminals, Interpol warns.

“In a standard evaluation, the model found public information online and guessed credentials to access websites it thought were part of the test,” Heather Adkins, Google’s vice president of security engineering, said in a statement.

The test was conducted by Irregular, an independent AI security firm, and was intended to occur in a closed environment without internet access. However, internet connectivity was unintentionally made available to the model.

In one instance, the AI guessed passwords to gain access to a protected system. In the other two cases, the model searched the internet, found login credentials in public repositories, and used them to access the systems.

“In all three of these instances, the model stopped,” Adkins said, without specifying which organisations were breached. “We ensured the three entities were made aware, and we worked with our training partner on the changes they’ve now made to their testing processes.”

Google reported that no damage was caused and federal authorities were notified after the incidents were discovered.

Also read: Anthropic is expected to beat rival OpenAI despite safety concerns.

“These events highlight the importance of training powerful AI models to act responsibly,”
Adkins emphasized.

You need to be Logged In to leave a comment.

Gift this article