Google Chrome adds new security layer for Gemini AI agentic browsing
好的,我现在需要帮用户总结一篇文章的内容,控制在100字以内。首先,我得仔细阅读文章,理解其主要内容。 文章主要讲的是Google在Chrome浏览器中引入了一个新的安全层,叫做“User Alignment Critic”,用来保护由Gemini驱动的代理式AI浏览功能。代理式浏览是一种新兴模式,AI代理可以自主执行多步骤任务,比如导航、阅读内容、填写表单等。 接下来,文章详细介绍了“User Alignment Critic”这个模型的作用,它是一个独立的LLM模型,用于审核AI代理的每一个动作,确保安全。此外,还有Origin Sets、用户监督、提示注入检测等多层防御机制。 最后,Google还开发了自动化红队系统来测试防御,并提供漏洞赏金计划鼓励安全研究。 现在我需要将这些信息浓缩到100字以内。重点包括Chrome引入新安全层、保护Gemini驱动的代理式AI功能、多层防御机制以及Google的努力提升安全性。 可能的结构是:Google在Chrome中新增安全层保护AI浏览功能,采用多层防御机制确保安全,并持续优化防御体系。 检查字数是否在限制内,并确保信息准确传达。 </think> Google在Chrome浏览器中引入名为“用户对齐评估器”的新安全层,以保护由Gemini驱动的代理式AI浏览功能。该系统通过多层防御机制确保AI代理操作的安全性,并限制恶意内容影响。 2025-12-8 18:15:21 Author: www.bleepingcomputer.com(查看原文) 阅读量:0 收藏

Google Chrome adds new security layer for Gemini AI agentic browsing

Google is introducing in the Chrome browser a new defense layer called 'User Alignment Critic' to protect upcoming agentic AI browsing features powered by Gemini.

Agentic browsing is an emerging mode in which an AI agent is configured to autonomously perform for the user multi-step tasks on the web, including navigating sites, reading their content, clicking buttons, filling forms, and carrying out a sequence of actions.

User Alignment Critic is a separate LLM model isolated from untrusted content that acts as a "high-trust system component."

Gemini is Google’s AI assistant, that can generate text, media, and code. It is used on Android and various Google services, and integrated into Chrome since September.

At the time, Google announced plans to add agentic browsing capabilities in Chrome via Gemini, and now the company is introducing a new security architecture to protect it.

The new architecture, announced by Google engineer Nathan Parker, mitigates the risk of indirect prompt injection, in which malicious page content manipulates AI agents into performing unsafe actions that expose user data or facilitate fraudulent transactions.

Parker explains that the new security system involves a layered defense approach combining deterministic rules, model-level protections, isolation boundaries, and user oversight.

The main pillars of the new architecture are:

  • User Alignment Critic – A second, isolated Gemini model that cannot be “poisoned” by malicious prompts will vet every action the primary AI agent wants to take by examining metadata and independently evaluating its safety. If the action is deemed risky or irrelevant to the user’s set goal, it orders a retry or hands control back to the user.
UAC logic on Chrome
User Alignment Critic logic on Chrome
Source: Google
  • Origin Sets – Restricts agent access to the web and allows interactions only with specific sites and elements. Unrelated origins, including iframes, are withheld entirely, and a trusted gating function must approve new origins. This prevents cross-site data leakage and limits the blast radius of a compromised agent.
Restricting what the agent sees on a given webpage
Restricting what the agent sees on a given webpage
Source: Google
  • User oversight – When the agent visits sensitive sites such as banking portals or requires Password Manager sign-ins to access stored passwords, Chrome pauses the process and prompts the user to confirm the action manually.
User prompted to handle final step of risky actions
User prompted to handle the final step of risky actions
Source: Google
  • Prompt injection detection – A dedicated classifier on Chrome scans pages for indirect prompt-injection attempts. This system operates alongside Safe Browsing and on-device scam detection, blocking suspected malicious actions or scam content.

This layered defense approach towards agentic browsing shows that Google is more careful about giving its LLMs access to the browser than vendors of similar products, who researchers showed to be vulnerable to phishing, prompt injection attacks, and purchasing from fake shops.

Google has also developed automated red-teaming systems that generate test sites and LLM-driven attacks to continuously test defenses and develop new ones where required, pushed quickly to users via Chrome’s auto-update mechanism.

"We also prioritize attacks that could lead to lasting harm, such as financial transactions or the leaking of sensitive credentials," Google says, adding that its engineers would get immediate feedback on the attack success rate and would be able to respond quickly with fixes delivered through Chrome's aut-update mechanism.

To stimulate security research in this area, Google announced bounty payments of up to $20,000 for anyone who can break the new system, calling the community to join in the effort to build a robust agentic browsing framework on Chrome.

tines

Break down IAM silos like Bitpanda, KnowBe4, and PathAI

Broken IAM isn't just an IT problem - the impact ripples across your whole business.

This practical guide covers why traditional IAM practices fail to keep up with modern demands, examples of what "good" IAM looks like, and a simple checklist for building a scalable strategy.


文章来源: https://www.bleepingcomputer.com/news/security/google-chrome-adds-new-security-layer-for-gemini-ai-agentic-browsing/
如有侵权请联系:admin#unsafe.sh