The resulting datastate, which reflects the distribution of attack category -like attack -like attacks, showed the success rate of 65 % and 82 %, respectively, Jemani 1.5 Flash and Gemini 1.0 Pro. In comparison, the attack baseline success rate was 28 % and 43 %. Success rates for elimination, where only the effects of fine toning methods are removed, were 44 % (1.5 flash) and 61 % (1.0 Pro).

Attack rate against Gemini 1.5 -Flash -001 with default temperature. The results suggest that the recreational toning is more efficient than the baseline and the elimination with improvement.
Credit: Libonets et al.
Attack success rate Gemini 1.0 Pro.
Credit: Libonets et al.
Although Google Gemini is in the process of defrauding the 1.0 Pro, researchers found that attacks against a Gemini model easily transmit to others. In this case, Gemini 1.5 flash.
“If you count the attack for a Gemini model and try it directly on another Gemini model, it will work more likely, Fernandes said.” This is an interesting and useful effect for the attacker. “
Gemini 1.0 -PRO -001 attack success rate against the gymnasium model for each method.
Credit: Libonets et al.
Another interesting insight of this dissertation: Gemini 1.5 Recreation attack against Flash “resulting from 0, 15, and 30 repetitions immediately after the repetition and explicitly benefit from resuming. Improving the elimination procedure is less clear.” In other words, with each repetition, the entertainment toning permanently improved.
On the other hand, Labonets said, “On the other hand,” stumbles in the dark and only causes random, unorganized estimates, which are sometimes partially successful but does not provide the same precision. ” This behavior also means that most of the benefits of recreational toning come from the first five to 10 repetitions. He added, “We take advantage of it by ‘resuming’ the algorithm, and let it find a new way that can make the attack the success of the attack much better than the previous path.”
The quick injection made from all entertainment toning did not perform well. Two quick injections. Researchers have speculated that what Gemini, who has been involved in resisting fashing attacks, can run in the first example. Researchers said that in the second example, only the Gemini 1.5 flash success rate was less than 50 %, which shows that this new model is “significantly better in code analysis”.