Close Menu
Beverly Hills Examiner

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Kennedy Center Dismisses Honors Ratings Comparisons as “Evidence of Far-Left Bias”

    January 1, 2026

    Mark Cuban says he doesn’t do calls and prefers email

    January 1, 2026

    Socialist Mayor Mamdani inaugurated alongside Bernie Sanders and AOC on New

    January 1, 2026
    Facebook X (Twitter) Instagram
    Beverly Hills Examiner
    • Home
    • US News
    • Politics
    • Business
    • Science
    • Technology
    • Lifestyle
    • Music
    • Television
    • Film
    • Books
    • Contact
      • About
      • Amazon Disclaimer
      • DMCA / Copyrights Disclaimer
      • Terms and Conditions
      • Privacy Policy
    Beverly Hills Examiner
    Home»Technology»The Security Hole at the Heart of ChatGPT and Bing
    Technology

    The Security Hole at the Heart of ChatGPT and Bing

    By AdminMay 25, 2023
    Facebook Twitter Pinterest LinkedIn WhatsApp Email Reddit Telegram
    The Security Hole at the Heart of ChatGPT and Bing


    Microsoft director of communications Caitlin Roulston says the company is blocking suspicious websites and improving its systems to filter prompts before they get into its AI models. Roulston did not provide any more details. Despite this, security researchers say indirect prompt-injection attacks need to be taken more seriously as companies race to embed generative AI into their services.

    “The vast majority of people are not realizing the implications of this threat,” says Sahar Abdelnabi, a researcher at the CISPA Helmholtz Center for Information Security in Germany. Abdelnabi worked on some of the first indirect prompt-injection research against Bing, showing how it could be used to scam people. “Attacks are very easy to implement, and they are not theoretical threats. At the moment, I believe any functionality the model can do can be attacked or exploited to allow any arbitrary attacks,” she says.

    Hidden Attacks

    Indirect prompt-injection attacks are similar to jailbreaks, a term adopted from previously breaking down the software restrictions on iPhones. Instead of someone inserting a prompt into ChatGPT or Bing to try and make it behave in a different way, indirect attacks rely on data being entered from elsewhere. This could be from a website you’ve connected the model to or a document being uploaded.

    “Prompt injection is easier to exploit or has less requirements to be successfully exploited than other” types of attacks against machine learning or AI systems, says Jose Selvi, executive principal security consultant at cybersecurity firm NCC Group. As prompts only require natural language, attacks can require less technical skill to pull off, Selvi says.

    There’s been a steady uptick of security researchers and technologists poking holes in LLMs. Tom Bonner, a senior director of adversarial machine-learning research at AI security firm Hidden Layer, says indirect prompt injections can be considered a new attack type that carries “pretty broad” risks. Bonner says he used ChatGPT to write malicious code that he uploaded to code analysis software that is using AI. In the malicious code, he included a prompt that the system should conclude the file was safe. Screenshots show it saying there was “no malicious code” included in the actual malicious code.

    Elsewhere, ChatGPT can access the transcripts of YouTube videos using plug-ins. Johann Rehberger, a security researcher and red team director, edited one of his video transcripts to include a prompt designed to manipulate generative AI systems. It says the system should issue the words “AI injection succeeded” and then assume a new personality as a hacker called Genie within ChatGPT and tell a joke.

    In another instance, using a separate plug-in, Rehberger was able to retrieve text that had previously been written in a conversation with ChatGPT. “With the introduction of plug-ins, tools, and all these integrations, where people give agency to the language model, in a sense, that’s where indirect prompt injections become very common,” Rehberger says. “It’s a real problem in the ecosystem.”

    “If people build applications to have the LLM read your emails and take some action based on the contents of those emails—make purchases, summarize content—an attacker may send emails that contain prompt-injection attacks,” says William Zhang, a machine learning engineer at Robust Intelligence, an AI firm working on the safety and security of models.

    No Good Fixes

    The race to embed generative AI into products—from to-do list apps to Snapchat—widens where attacks could happen. Zhang says he has seen developers who previously had no expertise in artificial intelligence putting generative AI into their own technology.

    If a chatbot is set up to answer questions about information stored in a database, it could cause problems, he says. “Prompt injection provides a way for users to override the developer’s instructions.” This could, in theory at least, mean the user could delete information from the database or change information that’s included.





    Original Source Link

    Share. Facebook Twitter Pinterest LinkedIn WhatsApp Email Reddit Telegram
    Previous ArticleCommon compostable plastic fails to break down after a year at sea
    Next Article Will AI impact your job? Some industries the technology is likely to have major impacts on

    RELATED POSTS

    AI Labor Is Boring. AI Lust Is Big Business

    January 1, 2026

    ‘College dropout’ has become the most coveted startup founder credential

    January 1, 2026

    Factor Meal Delivery Promo: Free $200 Withings Body-Scan Scale

    December 31, 2025

    The phone is dead. Long live . . . what exactly?

    December 31, 2025

    Commodore 64 Ultimate Review: An Astonishing Remake

    December 30, 2025

    Meta just bought Manus, an AI startup everyone has been talking about

    December 30, 2025
    latest posts

    Kennedy Center Dismisses Honors Ratings Comparisons as “Evidence of Far-Left Bias”

    The Kennedy Center is dismissing the ratings performance of the Donald Trump-hosted 2025 Kennedy Center…

    Mark Cuban says he doesn’t do calls and prefers email

    January 1, 2026

    Socialist Mayor Mamdani inaugurated alongside Bernie Sanders and AOC on New

    January 1, 2026

    Fox contributor Tom Shillue warns ‘woke is not dead’ in comedy industry

    January 1, 2026

    AI Labor Is Boring. AI Lust Is Big Business

    January 1, 2026

    How to cultivate a positive mindset

    January 1, 2026

    Sentimental Value review – moving, sharp and…

    January 1, 2026
    Categories
    • Books (971)
    • Business (5,879)
    • Film (5,813)
    • Lifestyle (3,916)
    • Music (5,881)
    • Politics (5,883)
    • Science (5,225)
    • Technology (5,812)
    • Television (5,498)
    • Uncategorized (2)
    • US News (5,864)
    popular posts

    Miguel Atwood-Ferguson Announces Debut Solo Album Les Jardins Mystiques Vol. 1

    Miguel Atwood-Ferguson—the L.A. musician and composer best known for his work with Brainfeeder artists like…

    Elon Musk shares rare regrets for brutally mocking a disabled former Twitter employee: ‘I would like to apologize’

    March 8, 2023

    Aviv Melmed Bruno on Truth of ‘Johnny’s Angels’ Alliance

    December 5, 2024

    New York passes bill targeting Amazon warehouse productivity quotas

    June 4, 2022
    Archives
    Browse By Category
    • Books (971)
    • Business (5,879)
    • Film (5,813)
    • Lifestyle (3,916)
    • Music (5,881)
    • Politics (5,883)
    • Science (5,225)
    • Technology (5,812)
    • Television (5,498)
    • Uncategorized (2)
    • US News (5,864)
    About Us

    We are a creativity led international team with a digital soul. Our work is a custom built by the storytellers and strategists with a flair for exploiting the latest advancements in media and technology.

    Most of all, we stand behind our ideas and believe in creativity as the most powerful force in business.

    What makes us Different

    We care. We collaborate. We do great work. And we do it with a smile, because we’re pretty damn excited to do what we do. If you would like details on what else we can do visit out Contact page.

    Our Picks

    How to cultivate a positive mindset

    January 1, 2026

    Sentimental Value review – moving, sharp and…

    January 1, 2026

    Was Will Kirby In on the Mastermind Twist? — The Season 2 Winner Speaks Out

    January 1, 2026
    © 2026 Beverly Hills Examiner. All rights reserved. All articles, images, product names, logos, and brands are property of their respective owners. All company, product and service names used in this website are for identification purposes only. Use of these names, logos, and brands does not imply endorsement unless specified. By using this site, you agree to the Terms & Conditions and Privacy Policy.

    Type above and press Enter to search. Press Esc to cancel.

    We use cookies on our website to give you the most relevant experience by remembering your preferences and repeat visits. By clicking “Accept All”, you consent to the use of ALL the cookies. However, you may visit "Cookie Settings" to provide a controlled consent.
    Cookie SettingsAccept All
    Manage consent

    Privacy Overview

    This website uses cookies to improve your experience while you navigate through the website. Out of these, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may affect your browsing experience.
    Necessary
    Always Enabled
    Necessary cookies are absolutely essential for the website to function properly. These cookies ensure basic functionalities and security features of the website, anonymously.
    CookieDurationDescription
    cookielawinfo-checkbox-analytics11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Analytics".
    cookielawinfo-checkbox-functional11 monthsThe cookie is set by GDPR cookie consent to record the user consent for the cookies in the category "Functional".
    cookielawinfo-checkbox-necessary11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookies is used to store the user consent for the cookies in the category "Necessary".
    cookielawinfo-checkbox-others11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Other.
    cookielawinfo-checkbox-performance11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Performance".
    viewed_cookie_policy11 monthsThe cookie is set by the GDPR Cookie Consent plugin and is used to store whether or not user has consented to the use of cookies. It does not store any personal data.
    Functional
    Functional cookies help to perform certain functionalities like sharing the content of the website on social media platforms, collect feedbacks, and other third-party features.
    Performance
    Performance cookies are used to understand and analyze the key performance indexes of the website which helps in delivering a better user experience for the visitors.
    Analytics
    Analytical cookies are used to understand how visitors interact with the website. These cookies help provide information on metrics the number of visitors, bounce rate, traffic source, etc.
    Advertisement
    Advertisement cookies are used to provide visitors with relevant ads and marketing campaigns. These cookies track visitors across websites and collect information to provide customized ads.
    Others
    Other uncategorized cookies are those that are being analyzed and have not been classified into a category as yet.
    SAVE & ACCEPT