Def Con Hackers Target AI Chatbots in Landmark Security Contest
LAS VEGAS — At this year's Def Con, the world's largest hacker gathering, the focus shifted from traditional targets like cars and smart homes to a new frontier: generative AI chatbots. A dedicated contest challenged attendees to find vulnerabilities in systems such as OpenAI's ChatGPT and Google's Bard, according to NBC News.
The event, held in Las Vegas, drew participation from six major AI companies, including Meta, Google, OpenAI, Anthropic, and Microsoft. The goal was to identify flaws in their generative AI tools, specifically through prompt injections — crafted inputs that can make chatbots produce unintended or harmful outputs. The White House announced its support for the event back in May, underscoring the growing concern over AI safety.
Why the Contest Matters
With billions of dollars pouring into the AI industry, the stakes are high. Rumman Chowdhury, a trust and safety consultant who helped design the contest, told NBC News that these companies are trying to commercialize their products. "Unless this model can reliably interact in innocent interactions, then it is not a marketable product," she said.
The contest's rules gave companies significant leeway. Any discovered vulnerabilities will not be publicized until February, giving firms time to address them. Hackers were also restricted to using provided laptops to access the systems, limiting the scope of potential attacks.
Persistent Vulnerabilities
Despite the effort, experts remain skeptical about the long-term fixes. Carnegie Mellon researchers recently demonstrated that chatbot guardrails can be easily bypassed with simple prompt injections, turning these tools into potential vectors for disinformation and discrimination. Zico Kolter, a professor at Carnegie Mellon and co-author of the report, told the New York Times last month, "There is no obvious solution. You can create as many of these attacks as you want in a short amount of time."
Tom Bonner, a speaker at Def Con from the AI security firm HiddenLayer, echoed this sentiment to the Associated Press, stating, "There are no good guardrails."
Further complicating matters, researchers at ETH Zurich in Switzerland found that a simple collection of images and text could be used to "poison" AI training data, with potentially devastating effects. This suggests that the problem extends beyond just chatbot interactions to the very foundation of AI models.
Chowdhury acknowledged the ongoing challenge, telling NBC News, "Misinformation is going to be a lingering problem for a while." The contest at Def Con is a step toward addressing these issues, but the path to reliable AI remains uncertain.