08.07.2025
Blog
Data & AI
Cyber Security

Using language models securely: How to protect AI from manipulation

Large language models such as ChatGPT and Gemini are impressive – but they are not invulnerable. Manipulation through misinformation or hidden instructions poses a real threat. That is why new security strategies are needed. Materna shows how it can be done.

Eduard Hübner
IT security expert

What if your AI solution were to provide systematically manipulated information? That is exactly what can happen – for example, through so-called ‘LLM grooming’ attacks. In such attacks, attackers flood the internet with targeted false information. Language models that access external data uncritically adopt this content. The result: incorrect answers, distorted narratives – and, in the worst-case scenario, misjudgements with real-world consequences.

Backdoor attack: indirect prompt injections

Another point of entry is what are known as ‘indirect prompt injections’. Attackers hide instructions within seemingly harmless content – such as a website or an email. If this information is processed by a language model, it can lead to unexpected behaviour: the AI no longer follows the user, but the attacker.

Traditional IT security falls short here. That is why Materna relies on a comprehensive security concept – from architecture right through to live operation: 

  • Least Privilege: Language models are only granted access to data that is absolutely essential.
  • Input filters: Incoming content is checked for suspicious patterns.
  • Monitoring: Unusual activity is automatically detected.
  • Distributed responsibility: Security mechanisms operate at multiple levels. 

Protective measures in practice

Some tried-and-tested strategies: 

  • Scanning before processing: Specialised models check inputs before they reach the main model.
  • Dual-LLM approaches: one model analyses, the other responds – without direct access to raw data.
  • Static and dynamic code analysis: This enables security vulnerabilities to be identified and rectified at an early stage. 

Stress testing for AI – using real-world attacks

Security testing does not end with go-live. Materna relies on regular penetration tests, for example using NVIDIA’s open-source tool garak. It simulates realistic attacks on AI systems – from simple jailbreaks to complex prompt injections. This is the only way to reliably identify and rectify vulnerabilities.

Conclusion: Security is not a state, but a process

AI can speed up processes and improve decision-making. However, without suitable protective measures, it quickly becomes a risk. Therefore, anyone wishing to use AI securely and responsibly must factor in security from the outset – technologically, strategically and continuously.

AI white paper available for download

Have you seen our AI white paper yet? You can download it here!

Eduard Hübner
IT security expert

Eduard Hübner is an IT security expert who specialises in the intersection of artificial intelligence and cyber security. Through his research, he contributes to the security of AI systems, whilst always striving to strike the right balance between security and flexibility in these systems.

Related articles

Short News
Think ahead
Cyber Security
26.08.2026
Quantum computers: The end of encryption as we know it

Why post-quantum readiness extends far beyond cryptography and is becoming a key prerequisite for digital sovereignty – for public administration, critical infrastructure, industry and all organisations with data that requires long-term protection.

Read more
Blog
Cyber Security
11.08.2026
Detecting and intercepting drones: the solutions are already available

How well are critical infrastructures protected against drone attacks? The security incident at Leipzig/Halle Airport has sent shockwaves through…

Read more
Blog
Cyber Security
11.08.2026
Cyber Security 2026: These trends are shaping both the business sector and public administration

In 2026, cyber security will be more of a focus than ever for businesses, government agencies and public institutions. According to the Lünendonk…

Read more
Short News
Corporate
Cyber Security
31.07.2026
From Rising Star to Leader: Materna has been recognised as a Leader in Strategic Security Services in the ISG Provider Lens™ Cyber Security – Services and Solutions 2026

ISG has recognised Materna as a leading provider of cyber security consultancy in Germany.

Read more
Blog
Cyber Security
28.07.2026
Security by Design: Why secure software isn’t just created just before going live

In many software projects, security is still viewed as a final testing step. Once the application is almost complete, security scans, penetration…

Read more
Blog
Cyber Security
21.07.2026
Information security: Clear lines of responsibility strengthen cyber resilience

Information security rarely fails due to a lack of awareness alone – it is often unclear lines of responsibility, a lack of coordination and…

Read more
Blog
Cyber Security
13.05.2026
KRITIS Framework Act: These new requirements now apply to KRITIS operators

The protection of critical infrastructure has been a key issue for many businesses and public authorities for years. With the new KRITIS framework law…

Read more
Blog
Cyber Security
24.03.2026
Cyber resilience in small and medium-sized enterprises: Why cyber security today determines the future

Cyber resilience in small and medium-sized enterprises is no longer merely an optional IT issue, but a strategic necessity. Whilst large corporations…

Read more
Blog
Cyber Security
30.10.2025
A systematic approach to information security: Why an ISMS is essential

In an age of growing cyber threats and complex digital interdependencies, information security has long since become a strategic factor for success.…

Read more
Blog
Data & AI
Cyber Security
28.10.2025
Prompt Injection – How AI can be misled by hidden commands

Imagine this: you ask a chatbot to summarise a web page. At first glance, the text seems completely harmless, but hidden somewhere in the small print…

Read more