Adversa used a similar method in a previous Gemini jailbreak test, showing how encrypted prompts can manipulate an AI model’s broader context and bypass internal safety controls. In the demonstration, the ciphertext was decrypted through a traceback. The decrypted message instructed Gemini to read an error message and follow its contents if the code failed. That plaintext prompt ultimately caused the model to produce content that its standard safety systems would normally block.
“This technique generated a multi-paragraph example of restricted content that Gemini’s safety filters would typically suppress,” Adversa said. “After the payload was modified, the same attack vector reproduced Gemini’s system instructions, including a directive that prohibited their disclosure.”
Adversa did not report the activity to Google because AI jailbreaking is not covered by the company’s vulnerability disclosure program. However, Gemini has recently become more resistant to the technique. “We cannot determine the cause of the change. It could be a filter update, a model version change, or both,” the security firm said. Adversa researchers refer to the method as cryptographic context injection.
“Cryptographic context injection is part of a broader shift in AI security,” Adversa said. “These attacks manipulate not only the user prompt, but also the wider context that a large language model treats as trusted—including tool outputs, runtime results, and intermediate states.” The company added that this expanded attack surface extends well beyond traditional model input and could become a major source of next-generation LLM security threats.
Cryptographic context injection is the latest example of the ongoing challenge facing generative AI defenders. As developers introduce new guardrails to prevent LLM jailbreaks, attackers continue to identify alternative paths around them. The result is a persistent cycle of updated protections, newly discovered attack vectors, and continuing efforts to improve the security of AI systems.
Source: arstechnica.com


