#18 Dec 22
Kikimora Morozova, Security Researcher at Trail of Bits
--:--
An attacker can hide prompt injections in images that only become to AI systems, enabling data exfiltration on production systems like Google Gemini CLI. Is weaponized image scaling a security vulnerability, or an architectural flaw in how AI systems process multi-modal inputs?
Listen on