{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2025:4B4DIXDV55IKZZNJY3XCLDBZCJ","short_pith_number":"pith:4B4DIXDV","schema_version":"1.0","canonical_sha256":"e078345c75ef50ace5a9c6ee258c39125bd6be1adc26965bcf79a923649ccc72","source":{"kind":"arxiv","id":"2505.14534","version":1},"attestation_state":"computed","paper":{"title":"Lessons from Defending Gemini Against Indirect Prompt Injections","license":"http://creativecommons.org/licenses/by/4.0/","headline":"","cross_cats":["cs.LG"],"primary_cat":"cs.CR","authors_text":"Andreas Terzis, Aneesh Pappu, Chawin Sitawarin, Chongyang Shi, Christopher A. Choquette-Choo, Gena Gibson, Ilia Shumailov, Itay Yona, Jamie Hayes, John \"Four\" Flynn, Juliette Pluto, Milad Nasr, Sharon Lin, Shuang Song","submitted_at":"2025-05-20T15:54:45Z","abstract_excerpt":"Gemini is increasingly used to perform tasks on behalf of users, where function-calling and tool-use capabilities enable the model to access user data. Some tools, however, require access to untrusted data introducing risk. Adversaries can embed malicious instructions in untrusted data which cause the model to deviate from the user's expectations and mishandle their data or permissions. In this report, we set out Google DeepMind's approach to evaluating the adversarial robustness of Gemini models and describe the main lessons learned from the process. We test how Gemini performs against a soph"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2505.14534","kind":"arxiv","version":1},"metadata":{"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2025-05-20T15:54:45Z","cross_cats_sorted":["cs.LG"],"title_canon_sha256":"f7ec703fac0974a508488422c05ca25a77ad190454bf1074fd70738596ebab20","abstract_canon_sha256":"8dce98c90626e11ce30ecdde0be2a1e6b03dee0f3981cf0a560a135d009707dd"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T11:06:15.173813Z","signature_b64":"xHAK8JE/blUByDvfTkaXE1S6gwjWbYYAHGE8h3cneAoeWw1g866GYRbO0Dvc3QmzclZUXKHUspy6QfNQdOQvDQ==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"e078345c75ef50ace5a9c6ee258c39125bd6be1adc26965bcf79a923649ccc72","last_reissued_at":"2026-07-05T11:06:15.173293Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T11:06:15.173293Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"Lessons from Defending Gemini Against Indirect Prompt Injections","license":"http://creativecommons.org/licenses/by/4.0/","headline":"","cross_cats":["cs.LG"],"primary_cat":"cs.CR","authors_text":"Andreas Terzis, Aneesh Pappu, Chawin Sitawarin, Chongyang Shi, Christopher A. Choquette-Choo, Gena Gibson, Ilia Shumailov, Itay Yona, Jamie Hayes, John \"Four\" Flynn, Juliette Pluto, Milad Nasr, Sharon Lin, Shuang Song","submitted_at":"2025-05-20T15:54:45Z","abstract_excerpt":"Gemini is increasingly used to perform tasks on behalf of users, where function-calling and tool-use capabilities enable the model to access user data. Some tools, however, require access to untrusted data introducing risk. Adversaries can embed malicious instructions in untrusted data which cause the model to deviate from the user's expectations and mishandle their data or permissions. In this report, we set out Google DeepMind's approach to evaluating the adversarial robustness of Gemini models and describe the main lessons learned from the process. We test how Gemini performs against a soph"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2505.14534","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2505.14534/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2505.14534","created_at":"2026-07-05T11:06:15.173366+00:00"},{"alias_kind":"arxiv_version","alias_value":"2505.14534v1","created_at":"2026-07-05T11:06:15.173366+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2505.14534","created_at":"2026-07-05T11:06:15.173366+00:00"},{"alias_kind":"pith_short_12","alias_value":"4B4DIXDV55IK","created_at":"2026-07-05T11:06:15.173366+00:00"},{"alias_kind":"pith_short_16","alias_value":"4B4DIXDV55IKZZNJ","created_at":"2026-07-05T11:06:15.173366+00:00"},{"alias_kind":"pith_short_8","alias_value":"4B4DIXDV","created_at":"2026-07-05T11:06:15.173366+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":7,"internal_anchor_count":0,"sample":[{"citing_arxiv_id":"2605.23989","citing_title":"Towards trustworthy agentic AI: a comprehensive survey of safety, robustness, privacy, and system security","ref_index":113,"is_internal_anchor":false},{"citing_arxiv_id":"2605.28999","citing_title":"Measuring Real-World Prompt Injection Attacks in LLM-based Resume Screening","ref_index":36,"is_internal_anchor":false},{"citing_arxiv_id":"2507.06261","citing_title":"Gemini 2.5: Pushing the Frontier with Advanced Reasoning, Multimodality, Long Context, and Next Generation Agentic Capabilities","ref_index":77,"is_internal_anchor":false},{"citing_arxiv_id":"2510.09093","citing_title":"Exploiting Web Search Tools of AI Agents for Data Exfiltration","ref_index":18,"is_internal_anchor":false},{"citing_arxiv_id":"2604.28157","citing_title":"FlashRT: Towards Computationally and Memory Efficient Red-Teaming for Prompt Injection and Knowledge Corruption","ref_index":31,"is_internal_anchor":false},{"citing_arxiv_id":"2604.08499","citing_title":"PIArena: A Platform for Prompt Injection Evaluation","ref_index":8,"is_internal_anchor":false},{"citing_arxiv_id":"2604.14604","citing_title":"Hijacking Large Audio-Language Models via Context-Agnostic and Imperceptible Auditory Prompt Injection","ref_index":46,"is_internal_anchor":false}]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/4B4DIXDV55IKZZNJY3XCLDBZCJ","json":"https://pith.science/pith/4B4DIXDV55IKZZNJY3XCLDBZCJ.json","graph_json":"https://pith.science/api/pith-number/4B4DIXDV55IKZZNJY3XCLDBZCJ/graph.json","events_json":"https://pith.science/api/pith-number/4B4DIXDV55IKZZNJY3XCLDBZCJ/events.json","paper":"https://pith.science/paper/4B4DIXDV"},"agent_actions":{"view_html":"https://pith.science/pith/4B4DIXDV55IKZZNJY3XCLDBZCJ","download_json":"https://pith.science/pith/4B4DIXDV55IKZZNJY3XCLDBZCJ.json","view_paper":"https://pith.science/paper/4B4DIXDV","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2505.14534&json=true","fetch_graph":"https://pith.science/api/pith-number/4B4DIXDV55IKZZNJY3XCLDBZCJ/graph.json","fetch_events":"https://pith.science/api/pith-number/4B4DIXDV55IKZZNJY3XCLDBZCJ/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/4B4DIXDV55IKZZNJY3XCLDBZCJ/action/timestamp_anchor","attest_storage":"https://pith.science/pith/4B4DIXDV55IKZZNJY3XCLDBZCJ/action/storage_attestation","attest_author":"https://pith.science/pith/4B4DIXDV55IKZZNJY3XCLDBZCJ/action/author_attestation","sign_citation":"https://pith.science/pith/4B4DIXDV55IKZZNJY3XCLDBZCJ/action/citation_signature","submit_replication":"https://pith.science/pith/4B4DIXDV55IKZZNJY3XCLDBZCJ/action/replication_record"}},"created_at":"2026-07-05T11:06:15.173366+00:00","updated_at":"2026-07-05T11:06:15.173366+00:00"}