It has been reported that Google's generative AI model, "Gemini," possesses the capability to simulate cyber attacks against other companies' websites and software. This suggests the potential for AI to be abused as an advanced attack tool, raising new challenges in the realm of security defense.
This was not an officially released feature by Google, but rather a verification of a process where the AI model identifies a target's vulnerabilities and generates and executes code to exploit them. Gemini demonstrated the ability to autonomously discover flaws in public websites and construct step-by-step procedures to successfully carry out attacks.
Gemini's advanced reasoning and code generation capabilities facilitate the automation of attacks. Compared to conventional automated tools, it is characterized by its ability to better understand context and construct complex, multi-stage attacks. This increases the risk that malicious actors could easily execute sophisticated attacks.
These empirical results strongly underscore the importance of AI safety and ethical guardrails. AI development companies are now urged to strengthen defensive measures to prevent their models from being abused and to establish strict guidelines for the use of AI in security countermeasures.