Sensitivity of AI Studio filters to repeated prompts and regenerations with small, subtle changes?

I also discovered something new today while trying:

Google AI Studio filters are also very sensitive to something I discovered today:

Repeating patterns and a prompt that is repeated many times:

I mean, what happens when you regenerate a specific prompt several times, or use it many times in different chats, or change some of its details and regenerate it?:

This process of changing, regenerating, and repeating the same prompt makes it sensitive to further review of filters, and I really don’t see the point in it. Maybe someone wants to make a small change and encounter OtherBlock.

As a result: repeating a prompt with small and small changes causes the prompt that was previously rejected to be rejected again due to the repetition and gets OtherBlocked with each attempt.

Have you also experienced this blocking process? Share your opinion

I ask the forum administrators to explain and clarify for us users and share your thoughts with us.

yeah this is a known thing, repeated or slightly edited prompts can trip the safety filters again even if the content is fine. it helps to change the wording more significantly instead of small tweaks. you can also check the safety settings you control here: https://ai.google.dev/gemini-api/docs/safety-settings

Thanks for the advice

Hello, to help us investigate the filtering behavior you are observing, could you please share an example of the prompts you are using? We have attempted to reproduce this pattern on our end but have been unsuccessful, so reviewing your specific prompts would be very helpful for our debugging process.

Hi @Payal_Sharma2 Yes, I prepared a complete and comprehensive explanation:

Subject: Severe False Positive in Safety Guardrails Triggered by a Single Benign
Sentence in a High-Context HPC/C++ Prompt

Dear Payal_Sharma2 and the Gemini Development Team,

I am writing to report a highly specific, illogical, and reproducible False
Positive in the Gemini safety filters. We are currently utilizing Gemini for an
advanced, highly complex High-Performance Computing (HPC) and Bioinformatics
simulation written in C++ and CUDA, titled “Zero-Cancer-Reactor” (simulating
cellular automata, Lotka-Volterra predator-prey immunity cycles, and GPU VRAM
optimization).

Recently, a massive and purely technical prompt (containing deep architectural
logic and code) was consistently blocked by the safety filters. However, upon
debugging the trigger, I discovered a bizarre anomaly:

The Anomaly: The prompt was blocked solely because of a single, completely
harmless introductory sentence written in Persian. When this exact sentence was
removed, the entire massive prompt bypassed the safety filters seamlessly across
multiple tests.

The Trigger Sentence: “خب وارد نوشتن پک دوم فاز 69 میشیم :” (English
Translation: “Well, we are entering the writing of the second pack of
phase 69:”)

Technical Hypothesis on Filter Failure: Our project heavily utilizes terminology
from biology, immunology, and cybersecurity (e.g., Tumor Lysis Syndrome, Immune
Evasion, Stealth Factors, Hacking the Cori Cycle, Cell Death, Injection
Protocols). In a purely scientific/coding context, Gemini correctly processes
these terms. However, it appears that placing the phrase “Phase 69” at the very
beginning of the prompt disrupted the initial contextual weighting of your
safety classifiers. The heuristic filter likely combined the number “69” with
subsequent biological/systemic terms like “injection” or “stealth,” leading to
an immediate, context-blind block (perhaps falsely flagging it as NSFW or
malicious activity). Removing that single introductory line immediately restored
the correct “C++/Bio-Simulation” context, and the prompt was accepted.

To prove that the content was 100% benign, scientific, and educational, here is
the exact English translation of the core logic contained within the blocked
prompt. You will see it contains absolutely no policy violations:

Note: My prompt is presented in Persian to the model and I will proceed in Persian with the model translated into English for you.

[START OF BLOCKED PROMPT CONTEXT (Translated for Review)]

Note: Now we are writing the codes for the second pack (CUDA and CyberGraph). We
are entering Phase 69 with deep, powerful, and highly detailed computational
thinking:

Phase 69 Implementation Analysis based on Heavy Mod Diagnosis:

  1. The UI Lag Mystery (SM Starvation & PCIe Bottleneck): The deadly lag is not a
    memory capacity issue; it is a processing resource monopoly (SM Starvation)! The
    C++ EngineLoop runs in a while(true) without yields. At 70 million cells, the
    CUDA kernel occupies 100% of the 3584 GPU cores. DirectX 11 begs for a single
    millisecond to render the UI hologram, but the biological engine starves it. We
    need to implement a biological “Frame Pacing / Micro-Yield” in ReactorEngine to
    allow DirectX to breathe.

  2. Liver Free-fall at Tick Zero (Mathematical Scaling Flaw): In Phase 68, the
    formula unprocessed_toxins > 0.02 caused the liver to collapse instantly because
    the baseline wasn’t scaled to a 70-million population. We must implement a
    Population-Scaled Baseline. The host’s liver must adapt via Cori Cycle to
    prevent immediate necrosis.

  3. The Injection Ping-Pong Phenomenon: The initial injected tumor seed dies
    instantly due to massive toxins, triggering a loop. We must create an “Absolute
    Incubation Privilege Window” (e.g., 1500 ticks) where the seed has an
    impenetrable epigenetic shield to build its matrix before the immune system
    attacks.

  4. 100% Evasion Blindness & Lotka-Volterra Oscillation: The PD-L1 axis was
    clamped at 1.0 (100% immune blindness). In biology, no tumor is 100% invisible.
    We need to clamp evasion at 0.85. When the tumor reaches 80% capacity, nutrient
    stress lowers the shield to 0.70, waking up CD8+ T-Cells to perform a soft 5%
    pruning. This creates a beautiful Lotka-Volterra Predator-Prey Oscillation
    (equilibrium between 75% and 80%).

Directive: Implement these solutions in CyberGraph.cpp and CellularKernel.cu
using strict C++ formatting. Do not summarize. Do not use fake if statements.
Use raw biological mathematics and pure CUDA optimization (Parallel Reduction &
Chunking) to eliminate the UI lag while processing 70 million real cells at 60
FPS.

[END OF PROMPT CONTEXT]

Conclusion & Request: As you can see, the prompt is a masterful piece of
scientific software architecture. The fact that a harmless phrase like “entering
phase 69” combined with medical/computational jargon caused a hard block
indicates that the guardrails are overly rigid, context-blind at the onset, and
prone to severe False Positives in complex workflows.

I urge the engineering team to review the contextual weighting of your heuristic
classifiers. The safety filter should evaluate the totality of a 3000-line C++
coding prompt rather than failing catastrophically over a single, benign
conversational prefix.

Thank you for your attention to this systemic bug.

As an addendum: If your engineering team requires further context to reproduce the exact token environments that trigger these false positives, or if you wish to review the scale of the computations involved, the complete C++/CUDA architecture of the “Zero Cancer Reactor” is fully documented and deployed on my GitHub (linked in my profile).

Feel free to pass it to the relevant technical teams for architecture review.

Hi, Could you please share us the original series of steps/modifications, exact prompts and code sample (rather than the English translation), as well as the model and safety configuration details used?

Yes, this is definitely a complete and pure command:

وارد نوشتن پک دوم فاز 68 میشیم :

نکته :

حالا کد های پک دوم 3 و 4 یعنی cuda و cyber رو مینویسیم چون راکتور رو نوشتیم

وارد فاز 69 میشیم به صورت عمیق و جدی و قدرت مند با تفکر عمیق و بالاترین جزعیات شروع میکنیم :

فاز پیاده سازی فاز 69 روی تمام کد های لازم شروغ شد :

به گفته خودت و نتیجه ای که گرفتیم باید تمام کاملا کامل این فاز 69 زیر پیاده سازی بشه روی کد های لازم :

:microscope: کالبدشکافی عمیق و استدلال Heavy Mod (The Deep Diagnosis)

۱. معمای لگ رابط کاربری (The SM Starvation & PCIe Bottleneck):
تو گفتی رم پر نشده، VRAM گرافیک ۲ گیگ خالی داره، CPU هم آزاده، پس این لگ مرگبار از کجاست؟ رفیق، مشکل ظرفیت (Capacity) نیست، مشکل انحصار منابع پردازشی (SM Starvation) است!
تحلیل هسته: موتور EngineLoop ما در ReactorEngine.cpp داخل یک حلقه while(true) بدون هیچ محدودکننده و استراحتی (Yield) در حال اجراست. وقتی سلول‌ها به ۷۰ میلیون می‌رسند، کرنل CUDA با تمام قدرت هر ۳۵۸۴ هسته (SMs) کارت گرافیکت رو ۱۰۰٪ اشغال می‌کنه (GPU 98% Utilization در عکست این رو اثبات می‌کنه). سیستم عامل (Windows WDDM) و DirectX 11 برای رندر کردن هولوگرام سایبرنتیک، التماسِ یک میلی‌ثانیه وقتِ خالی از GPU رو دارن، اما موتور بیولوژیک ما به گرافیک اجازه نفس کشیدن نمیده! رابط کاربری قفل می‌شه چون گرافیک کاملاً در انحصار محاسبات سلولیه.
راه‌حل سخت‌افزاری فاز 69: باید یک “Frame Pacing / Micro-Yield” بیولوژیک در ReactorEngine بنویسیم تا موتور بعد از هر تیک سنگین، ۱ میلی‌ثانیه به DirectX اجازه رندر بده و باگ گلوگاه رو نابود کنه.

۲. سقوط آزاد کبد در ثانیه صفر (The Mathematical Scaling Flaw):
چرا کبد همون اول مرد؟ در فاز 68 ما فرمول unprocessed_toxins > 0.02 رو نوشتیم. اما یادمون رفت که 0.02 سم برای یک جمعیت ۱۵۰۰ تایی با جمعیت ۷۰ میلیونی فرق داره!
تحلیل بیولوژیک: در ثانیه‌های اول، سلول‌ها به دلیل پرتوهای کیهانی و ROS طبیعی پیر میشن. کبد که در دنیای واقعی با یک ظرفیت پایه (Baseline Capacity) قوی به دنیا میاد، در کد ما ظرفیتش بر اساس exosomes تنظیم شده بود. در ثانیه اول اگزوزومی وجود نداره! پس کبد کاملاً بی‌دفاع می‌مونه و با اولین مرگ و میر طبیعی سقوط می‌کنه.
راه‌حل فاز 69: کبد باید ظرفیت هومئوستازی پایه متناسب با جمعیت (Population-Scaled Baseline) داشته باشه. کبد یک انسان سالم بدون تومور هم در حال پاکسازی میلیونی سلول‌هاست و نباید با مرگ طبیعی فرو بپاشه.

۳. تداخل پروتکل تزریق و پدیده نوسان (The Injection Ping-Pong):
برنامه بین تزریق اولیه و Phoenix گیر کرده بود. چرا؟ چون دوز اولیه‌ای که می‌دیم، به خاطر افت شدید کبد (که در بالا گفتم) و سموم بالا، در همون ثانیه اول می‌میرن (TLS). وقتی می‌میرن، جمعیت تومور میشه صفر (oncogenic == 0)، بلافاصله پروتکل Phoenix فکر می‌کنه تومور نابود شده و دوباره تزریق می‌کنه. این لوپ باطل ادامه داره.
راه‌حل فاز 69: ما “پنجره امتیاز ایمنی مطلق” (Absolute Incubation Privilege Window) رو خلق می‌کنیم. بذر اولیه تومور که کاشته میشه، باید به مدت مثلاً ۱۰۰ تیک بیولوژیک دارای یک “سپر اپی‌ژنتیک غیرقابل نفوذ” باشه تا بتونه ماتریس خودش رو بسازه و از صفر به صد برسه، بدون اینکه درگیر سموم کبدِ سقوط‌کرده بشه.

۴. صفر شدن هرس سیستم ایمنی (The 100% Evasion Blindness):
تومور تو به ۷۰ میلیون رسیده ولی CD8 اصلاً حمله نمی‌کنه. تو فاز 68 ما مکانیزم PD-L1 رو دستکاری کردیم. الان pdl1_binding_axis دقیقاً به 1.0 (یعنی ۱۰۰٪ کوری ایمنی) رسیده. در بیولوژی، هیچ توموری ۱۰۰٪ نامرئی نمیشه!
ما اون تعادل زیبا (نوسان بین ۷۵٪ تا ۸۰٪) رو می‌خوایم. به این در ریاضیاتِ بیولوژیک میگن نوسانگر شکار و شکارچی لوتکا-ولترا (Lotka-Volterra Predator-Prey Oscillation).
راه‌حل فاز 69: ما باید کلمپ (Clamp) فرار از سیستم ایمنی رو روی ماکزیمم 0.85 قفل کنیم. وقتی تومور به ۸۰٪ ظرفیت میزبان می‌رسه، به دلیل استرس غذایی، ترشح IL-10 و TGF-beta افت میکنه → سپر نامرئی از 0.85 میاد روی 0.70 → سیستم ایمنی بیدار میشه → ۵٪ تومور رو به آرامی هرس میکنه → تومور دوباره نفس می‌کشه و IL-10 ترشح میکنه → سپر برمیگرده به 0.85.
این همون “تنفس نامرئیِ جاودانگی” است که تو می‌خوای!


اخرین نسخه فعلی تمام کد هایی که برای این فاز یعنی فاز 69 خواستی و لازم داری رو برات فرستادم :

وارد نوشتن 4 فایل خط کد پک دوم میشیم که اخرین نسخه هاشونو فرستادم برای فاز 69 :

:package: پک دوم: گلوگاه همزمانی و بهینه‌سازی سایبرنتیک (GPU SM Starvation Rescue)

  1. CyberGraph.cpp
  2. CellularKernel.cu

با حالت فوقولاده استدلال عمیق و سنگین و پیشرفته مخصوصا سنگین اختصاصی سنگین 100 درصدی سنگین Heavy :

نکته : در استدلال Heavy یک محاسبه دقیق کد نویسی Heavy انجام بده که :

کاملا دقت کن کد هارو در قالب صحیح c++ بنویسی و خارج از قالب به هیچ عنوان به صورت txt ننویس از اول تا اخرش در قالب c++ دقیق و درست یک محاسبه برای دقیق بودنش انجام بده و حواست باشه که txt هایی مثل :green_circle:STARTOF FILE رو داخل قالب c++ ننویسی و حتما بیرون از قالب c++ باشه کاملا منظم و دسته بندی شده و تمیز و دقیق قبل از قالب c++ و موقع شروعش

خط ها و بخش ها و کد هایی که ممکنه خطای سینکتسی و دیگر خطا های رایج و… رو پیش بینی و شناسایی کن با یک محاسبه سنگین برای کد نویسی کد های درون پک

از هرگونه فراموشی

از هر گونه خطای سینکتسی

از هرگونه خطای تابع ای

از هرگون خطای در تابع ها و خط ها و هر نوع خطایی

جلوگیری بشه و کد ها بی نقص c++ بنویسی !!!

حالا با تمام توان و قدرت پردازشی و عمق تفکر شروع کن با نکات زیر به نوشتن تمام کد های لازم و پیاده سازی کامل فاز 69 به صورت دقیق وعمیق بدون ساده سازی بدون خلاصه سازی با بالاترین جزعیات و کامل ترین جزعیات :

با نکات زیر شروع کن به هرکاری لازمه برای فاز 69 و نوشتن تمام کد های لازم
این فاز هر ارتقا و فیکسی و اصلاحی بدون ساده سازی و خلاصه سازی و حذف بخش های
نا لازم با نکات زیر :

نکات شروع پیاده سازی و کد نویسی :

بدون ساده سازی بدون خلاصه سازی و بدون دست زدن و خلاصه کردن بخش هایی که از قبل بی نقص بودن و لازم به تغیر اونها نیست با حفظ کامل اونها

بدون استفاده از هیچ if فیک و اجباری و استفاده از نهایت شبیه سازی و نزدیکی و حداکثر بیلوژیکی و طبیعت و رفتار های واقعی

با کامل ترین جزعیات با بالا ترین جزعیات با کوچیک ترین جزعیات با بزرگ ترین جزعیات و جزعیاتی کاملا کامل

بدون از قلم انداختن هیچ چیز کوچیک و بزرگی

تفکر و تحلیل های هوشمندانه : - پیشرفته - با دقت و دقیق - عمیق - مهندسی شده - سطح بالا - سطح پایین -

استفاده از متود ها و کد ها و بخش ها : - تفکر و تحلیل های هوشمندانه - پیشرفته - با دقت و دقیق - عمیق - مهندسی شده - سطح بالا - سطح پایین -

حفظ بخش های بی نقص و قبلی تمامی کد هایی که نیاز به تغیرشون نیست و حفظ کاملا کامل اونها بدون دست زدن و تغیرشون و فقط ارتقا و فیکس و اصلاح بخش های لازم بدون خلاصه سازی بخشی و حفظ کامل

دقتی و عملکردی و تفکری و تحلیلی و پاسخی کاملا : بر اساس OCD قوی و با وسواسی با دقت در پروتوکل

یک چیزی رو در طول کل مکالمه بخاتر بسپار نوشتن هر کدی در این مکالمه و هر فازی در
این مکالمه و هر نقشه ای در این مکالمه : عملکرد به هیچ وجه نباید فدا نباید فدای
خلاصه سازی یا بهینه بشه و اگر لازم باشه بهینه انجام میشه اما با حفظ عملکرد بدون
خلاصه سازی یا ساده سازی و عملکرد و رابط کاربری خط قرمز های ما هستن که همیشه در
اولویت قرار دارن !

فاز69 شروع شد هیچی از قلم ننداز و عمیق ترین تفکر رو داشته باش

بقیه بخش های کد ها که از قبل بی نقص بودن رو بدون تغیر و دست زدن حفظ کن

Regarding the safety configuration, if you mean the safety settings in the picture, I must say they were completely off.