Google Reveals 100,000-Prompt Attack on Gemini AI: Cloning Attempt Uncovered

Google has revealed a sophisticated campaign targeting its Gemini artificial intelligence chatbot, involving over 100,000 specialized prompts designed to extract the model’s underlying logic and reasoning processes. The effort, which Google characterizes as a form of reverse engineering, aimed to essentially clone the proprietary AI. This incident highlights a growing trend of malicious actors attempting to exploit and replicate advanced AI technologies, raising concerns about intellectual property theft and potential misuse.

The attacks, detailed in a recent Google report on malicious activity targeting Gemini, didn’t involve traditional hacking methods like breaching corporate systems. Instead, threat actors leveraged legitimate access through Gemini’s Application Programming Interface (API). This API is designed for developers to build applications powered by the chatbot, but was exploited to systematically probe the AI’s internal workings. According to Google, this allowed attackers to interact with the model in a seemingly authorized manner, gradually mapping its responses and internal logic. The company’s Threat Intelligence Group (GTIG) first observed this activity in February 2026, noting the scale and persistence of the attacks.

Reverse Engineering and the Pursuit of AI Cloning

Unlike typical cyberattacks focused on data breaches or system disruption, this campaign centered on “model extraction,” a technique where adversaries attempt to recreate a proprietary AI model by analyzing its outputs. Gemini, in its normal operation, provides final answers to user prompts without revealing the step-by-step reasoning behind them. However, the attackers attempted to circumvent this by crafting prompts specifically designed to force the model to expose its internal thought processes. One identified prompt, as reported by Google, instructed Gemini to maintain strict consistency in language between its reasoning and the user’s input, effectively attempting to unlock the AI’s decision-making pathways.

This isn’t simply academic curiosity. Successfully cloning a model like Gemini would grant adversaries access to a powerful AI capability without the significant investment required for independent development. As noted in a report by The Hacker News, the group behind the attacks, identified as UNC2970, is linked to North Korea and overlaps with known hacking collectives like Lazarus Group and Diamond Sleet. This connection raises concerns about potential state-sponsored motives and the use of cloned AI for malicious purposes, including disinformation campaigns and cyber espionage.

Google’s Gemini AI model is the target of a large-scale model extraction attempt. (Google)

The API as an Attack Vector

Google’s Gemini API allows developers to integrate the chatbot’s capabilities into their own applications. While this fosters innovation, it also presents a potential security vulnerability. The attackers exploited this legitimate access point to launch their probing campaign. According to Google, the sheer volume of prompts – exceeding 100,000 – was a key indicator of malicious intent. This isn’t a simple case of users testing the limits of the AI; it’s a coordinated effort to systematically deconstruct and replicate it.

The company views this activity as a form of intellectual property theft, violating Gemini’s Terms of Service. Google has stated its right to take action against those involved, including revoking API access. This incident serves as a warning to other AI developers about the potential for similar attacks and the need to implement robust security measures to protect their models. The scale of the attack, as reported by PCMag, underscores the growing sophistication of adversaries targeting AI systems.

Broader Implications for AI Security

The attempted cloning of Gemini isn’t an isolated incident. It reflects a broader trend of increasing attacks targeting AI models. Researchers and security experts have warned about the risks of model extraction and the potential for adversaries to weaponize stolen AI capabilities. The motivations behind these attacks can range from commercial gain to malicious intent, including the development of sophisticated phishing campaigns and the automation of cyberattacks. The UNC2970 group, previously known for its “Operation Dream Job” targeting aerospace, defense, and energy sectors, demonstrates a clear pattern of using advanced techniques to compromise high-value targets.

Google’s response to this attack highlights the importance of proactive security measures in the AI landscape. This includes monitoring API usage for suspicious activity, implementing rate limiting to prevent abuse, and developing techniques to detect and mitigate model extraction attempts. The company is also working with the broader AI community to share best practices and develop collective defenses against these emerging threats. The incident also raises questions about the ethical implications of AI cloning and the need for stronger legal frameworks to protect intellectual property in the age of artificial intelligence.

Key Takeaways

  • Large-Scale Attack: Over 100,000 prompts were used in an attempt to extract the logic of Google’s Gemini AI model.
  • Reverse Engineering: The attack aimed to clone Gemini through systematic probing of its API.
  • State-Sponsored Link: The threat actor, UNC2970, is linked to North Korea and known hacking groups like Lazarus Group.
  • Intellectual Property Theft: Google considers this a violation of its Terms of Service and a form of intellectual property theft.
  • Growing Threat: This incident highlights the increasing risk of attacks targeting AI models and the need for robust security measures.

Google continues to investigate the incident and refine its security protocols. The company has not disclosed the full extent of the information potentially compromised, but has assured users that it is taking all necessary steps to protect its AI models and user data. Further updates on this evolving situation are expected in the coming weeks, as Google continues to analyze the attack and implement countermeasures. The incident underscores the critical need for ongoing vigilance and collaboration in the face of increasingly sophisticated threats to artificial intelligence systems.

Readers interested in learning more about AI security and the risks of model extraction are encouraged to follow updates from Google’s Threat Intelligence Group and security research organizations. Share your thoughts on this developing story in the comments below.

Leave a Comment