Phil 2.13.2025

Guardian between 10:00 – 11:00

New hack uses prompt injection to corrupt Gemini’s long-term memory

  • Rehberger’s delayed tool invocation demonstration targeted Gemini, which at the time was still called Bard. His proof-of-concept exploit was able to override the protection and trigger the Workspace extension to locate sensitive data in the user’s account and bring it into the chat context.

SBIRs

  • 9:00 standup
  • 11:00 rates
  • 4:30 book club?
  • More data generation – done with the file generation

GPT Agents

  • More slides – add the new slides to the end of the old ones. Match the format
  • More conclusions