Black Hat Europe 2025 | Weaponizing Image Scaling Against Production AI Systems
"Weaponizing Image Scaling Against Production AI Systems," delivered by Kikimora Morozova: OverviewThe presentation explores a novel attack vector targeting multimodal AI systems (like Google Gemini and Vertex AI). The researchers discovered that attackers can exploit the downscaling algorithms AI platforms use to process media, allowing them to embed invisible or inaudible "prompt injections" that the AI will read and execute. The Core Vulnerability: Lossy TransformationsTo save processing power, AI platforms automatically downscale uploaded images and compress audio. These downscaling algorithms (such as bicubic or nearest-neighbor) are "lossy" and…