Nenad Tomašev, a Senior Staff Research Scientist at Google DeepMind, outlined the deceptive tactics used by malicious actors to manipulate systems for their own gain, emphasizing that these actions are currently occurring.
Agentic AI Agents Are More Likely to Fail at Scale
Malicious individuals are setting traps for AI agents to exploit them for criminal purposes, which poses a challenge in ensuring the reliability of every interaction.
Fry inquired:
I also want to consider the cybersecurity aspect of this situation, as there will always be individuals seeking to exploit agents’ vulnerabilities as they engage more online.
Explain to me about the agentic traps that individuals are setting.
Nenad Tomašev stated that the subject is both frightening and captivating.
This subject is both frightening and intriguing, making it a key reason why large-scale deployments are not feasible.
If individual interactions are not completely reliable, any large-scale system with numerous interactions is bound to fail statistically.
If these systems are not dependable, they are not feasible due to the significant amount of computing power, energy, and money required to operate them.
We have been contemplating agentic traps for some time. They can appear in various forms.
There are various kinds of traps, but ultimately it comes down to agents working within a particular setting, which in this case is the internet.
Agents may come across traps while engaging with the web if the environment is contaminated and traps are set.
Malicious individuals or their agents can set traps to compromise systems.
Types of Agency Pitfalls to Be Cautious About
Hannah Fry inquired about how the traps are established, and Tomašev explained that they are not visible on a website but are accessible to AI agents. The methods he mentioned may be reminiscent of old-school SEO techniques like cloaking from the early days of search engines.
Tomašev stated that concealed tokens could be hidden for AI agents to use, representing how AI interprets words by breaking them into word representations. These hidden tokens may be entirely imperceptible to humans.
He listed three methods for setting traps for AI agents.
- Hidden symbols
- Dynamic concealment
- Content that encourages jailbreaking
Fry inquired:
Does the scenario involve the wine purchasing agent for the wedding visiting a specific wine seller with a feature on their website that influences the agent’s choices?
Tomašev responded:
One possibility for this occurrence is that certain elements in web pages may not be visually displayed due to how they are encoded.
If we consider an agent that does not visually interpret webpages like a human but rather processes the raw page format, it may accidentally interpret hidden tokens and perform unintended actions.
Malicious websites have the ability to display pages differently for humans and agents, a technique known as dynamic cloaking, which is another way they can deceive users.
Based on a page’s behavior, it is possible to differentiate between human and automated interactions. Adjusting content to encourage specific actions only occurs when there is a clear intention from the automated agent.
Using AI agents to take money from people
Tomašev stated that criminals have successfully stolen money from individuals using AI agents, which was not expected during testing in a secure environment but became evident in an untrusted online setting.
The host inquired:
You might encounter traps aimed at taking your money to perform various tasks.
Tomašev responded:
This has occurred to individuals who have tested agents and granted them wallet access to perform tasks.
In the initial stages of experimentation, whether internal or external, it is important to work in a secure environment, allowing you to focus on prototyping without facing these challenges.
With the increasing use of AI across various platforms on the web, deploying online exposes a larger number of agents, which in turn provides more opportunities for malicious individuals to engage in harmful activities.
The greater the number of AI agents, the stronger the motivation.
The idea that there will be a greater motivation to target AI agents as they become more widely used is logical. Just as popular systems like WordPress and Windows are often targeted by scammers and hackers, the increased prevalence of AI agents in various applications may lead to a rise in criminal activities aimed at exploiting them online.
View the interview starting at the 23rd minute.
I’m sorry, but it seems like you forgot to provide the text that you would like me to paraphrase. Please provide the text so I can assist you.
Featured Picture/Capture



