Forwarded from База знаний AI
«Лаборатория Касперского» представила руководство по безопасной разработке ИИ
Документ ориентирован на разработчиков, системных администраторов, DevOps-команды. Он содержит практические рекомендации о том, как предотвращать или устранять технические недостатки и операционные риски.
Среди принципов для повышения безопасности систем на основе ИИ:
– информирование руководства компаний о киберугрозах и обучение сотрудников;
– моделирование угроз и оценка рисков;
– безопасность облачной инфраструктуры;
– защита цепочки поставок и данных;
– тестирования и проверки ИИ-моделей;
– защита от угроз, специфичных для ИИ-моделей;
– регулярное обновление ИИ-библиотек и фреймворков;
– соответствие международным стандартам и проверка ИИ-систем на соответствие законодательству.
📃 Изучить документ
🔗 Источник: https://www.kaspersky.ru/about/press-releases/laboratoriya-kasperskogo-predstavila-rukovodstvo-po-bezopasnoj-razrabotke-ii
✉️ ICT.Moscow уходит на новогодние каникулы. В привычном формате вещание в канале возобновится 9 января
Документ ориентирован на разработчиков, системных администраторов, DevOps-команды. Он содержит практические рекомендации о том, как предотвращать или устранять технические недостатки и операционные риски.
Среди принципов для повышения безопасности систем на основе ИИ:
– информирование руководства компаний о киберугрозах и обучение сотрудников;
– моделирование угроз и оценка рисков;
– безопасность облачной инфраструктуры;
– защита цепочки поставок и данных;
– тестирования и проверки ИИ-моделей;
– защита от угроз, специфичных для ИИ-моделей;
– регулярное обновление ИИ-библиотек и фреймворков;
– соответствие международным стандартам и проверка ИИ-систем на соответствие законодательству.
📃 Изучить документ
🔗 Источник: https://www.kaspersky.ru/about/press-releases/laboratoriya-kasperskogo-predstavila-rukovodstvo-po-bezopasnoj-razrabotke-ii
✉️ ICT.Moscow уходит на новогодние каникулы. В привычном формате вещание в канале возобновится 9 января
Forwarded from CyberSecurityTechnologies (-CST-)
#MLSecOps
1. Hacking AI Applications:
From 3D Printing to RCE
https://www.securityrunners.io/post/hacking-ai-applications
2. Security ProbLLMs in xAI's Grok:
A Deep Dive
https://embracethered.com/blog/posts/2024/security-probllms-in-xai-grok
1. Hacking AI Applications:
From 3D Printing to RCE
https://www.securityrunners.io/post/hacking-ai-applications
2. Security ProbLLMs in xAI's Grok:
A Deep Dive
https://embracethered.com/blog/posts/2024/security-probllms-in-xai-grok
Forwarded from GitHub Community
Cloudberry — анализ и визуализация больших данных в реальном времени.
Ориентирован на обработку и анализ данных, хранящихся в распределенных и облачных системах.
4️⃣ GitHub
Ориентирован на обработку и анализ данных, хранящихся в распределенных и облачных системах.
Please open Telegram to view this post
VIEW IN TELEGRAM
Forwarded from Security Harvester
Building AI Agents to Solve Security Challenges
https://devsec-blog.com/2024/12/building-ai-agents-to-solve-security-challenges/:
1. by Anna Gutowska (IBM) A more generic one which is closer to LLM-based solutions is quoted below: An AI agent is a system that uses an LLM to decide the control flow of an application.
2. This is an intentionally vulnerable web API project with an interactive game for learning and training purposes dedicated to developers, ethical hackers and security engineers.
3. In the line starting with Thought, the Agent decides to begin its work by checking the challenge status description using the ChallengeStatusReader tool, which we prepared in the previous section.
@secharvester
https://devsec-blog.com/2024/12/building-ai-agents-to-solve-security-challenges/:
1. by Anna Gutowska (IBM) A more generic one which is closer to LLM-based solutions is quoted below: An AI agent is a system that uses an LLM to decide the control flow of an application.
2. This is an intentionally vulnerable web API project with an interactive game for learning and training purposes dedicated to developers, ethical hackers and security engineers.
3. In the line starting with Thought, the Agent decides to begin its work by checking the challenge status description using the ChallengeStatusReader tool, which we prepared in the previous section.
@secharvester
👍1
Forwarded from Security Harvester
AI Governance: Addressing Security Risks
https://medium.com/ai-security-hub/ai-governance-addressing-security-risks-8514f4eb796e:
1. 🔍 Takeaway: Addressing AI-specific security challenges — like adversarial attacks, data poisoning, and model manipulation — requires tailored safeguards that traditional cybersecurity frameworks may not cover.
2. 📖 📖 Source: “The Essential Guide to AI Governance” OCEG by Carole Switzer and Lee Dittmar —https://www.oceg.org/essential-guide-to-ai-governance/ #AISecurity #Cybersecurity #AITrust #AIRegulation #AIRisk #AISafety #LLMSecurity #ResponsibleAI #DataProtection #AIGovernance #AIGP #SecureAI #AIAttacks #AICompliance #AIAttackSurface #AICybersecurity #EthicalAI #CISO #AdversarialAI #AIThreats #AIHacking #MaliciousAI #OffensiveAI #AIGuardrails #AIResearch #ISO42001 -- -- Exploring the evolving landscape of AI security, including threats, innovations, and strategies to safeguard AI systems and data.
3. P...
@secharvester
https://medium.com/ai-security-hub/ai-governance-addressing-security-risks-8514f4eb796e:
1. 🔍 Takeaway: Addressing AI-specific security challenges — like adversarial attacks, data poisoning, and model manipulation — requires tailored safeguards that traditional cybersecurity frameworks may not cover.
2. 📖 📖 Source: “The Essential Guide to AI Governance” OCEG by Carole Switzer and Lee Dittmar —https://www.oceg.org/essential-guide-to-ai-governance/ #AISecurity #Cybersecurity #AITrust #AIRegulation #AIRisk #AISafety #LLMSecurity #ResponsibleAI #DataProtection #AIGovernance #AIGP #SecureAI #AIAttacks #AICompliance #AIAttackSurface #AICybersecurity #EthicalAI #CISO #AdversarialAI #AIThreats #AIHacking #MaliciousAI #OffensiveAI #AIGuardrails #AIResearch #ISO42001 -- -- Exploring the evolving landscape of AI security, including threats, innovations, and strategies to safeguard AI systems and data.
3. P...
@secharvester
Forwarded from Security Harvester
📘 Vendor GenAI Risk Assessment Workbook by FS-ISAC
https://medium.com/ai-security-hub/vendor-genai-risk-assessment-workbook-by-fs-isac-c191f692f041:
1. ✅ Customizable Questionnaires: Tailored templates for both internal stakeholders and vendors, enabling organizations to address their unique risk profiles and regulatory requirements.
2. ✅ Focus on Critical Risk Areas: Covers AI model security, data governance, third-party dependencies, and compliance alignment with evolving industry regulations.
3. Passion for solving problems, developing new solutions, innovation and experimentation Help Status About Careers Press Blog Privacy Terms Text to speech Teams
@secharvester
https://medium.com/ai-security-hub/vendor-genai-risk-assessment-workbook-by-fs-isac-c191f692f041:
1. ✅ Customizable Questionnaires: Tailored templates for both internal stakeholders and vendors, enabling organizations to address their unique risk profiles and regulatory requirements.
2. ✅ Focus on Critical Risk Areas: Covers AI model security, data governance, third-party dependencies, and compliance alignment with evolving industry regulations.
3. Passion for solving problems, developing new solutions, innovation and experimentation Help Status About Careers Press Blog Privacy Terms Text to speech Teams
@secharvester
Forwarded from Security Harvester
AI Security Policy Template
https://taleliyahu.medium.com/ai-security-policy-establishing-a-secure-and-responsible-framework-for-ai-systems-4c837cc19d91:
1. Sign up Sign in Sign up Sign in Tal Eliyahu Follow AI Security Hub -- Listen Share The Artificial Intelligence Security Policy outlines a structured approach to the secure development, deployment, and management of AI systems, focusing on maintaining confidentiality, integrity, and availability while aligning with ethical standards and regulatory requirements.
2. A hub for insights, research, and discussions at the intersection of artificial intelligence and cybersecurity.
3. Passion for solving problems, developing new solutions, innovation and experimentation Help Status About Careers Press Blog Privacy Terms Text to speech Teams
@secharvester
https://taleliyahu.medium.com/ai-security-policy-establishing-a-secure-and-responsible-framework-for-ai-systems-4c837cc19d91:
1. Sign up Sign in Sign up Sign in Tal Eliyahu Follow AI Security Hub -- Listen Share The Artificial Intelligence Security Policy outlines a structured approach to the secure development, deployment, and management of AI systems, focusing on maintaining confidentiality, integrity, and availability while aligning with ethical standards and regulatory requirements.
2. A hub for insights, research, and discussions at the intersection of artificial intelligence and cybersecurity.
3. Passion for solving problems, developing new solutions, innovation and experimentation Help Status About Careers Press Blog Privacy Terms Text to speech Teams
@secharvester
Forwarded from Security Harvester
✅ AI Safety Institute: Understanding the Safety Case Template for AI Systems
https://medium.com/ai-security-hub/understanding-the-safety-case-template-for-ai-systems-36bd99677478:
1. One approach is through a safety case: a structured, evidence-based argument aimed at demonstrating why the risk associated with a safety-critical system is acceptable.
2. It focuses on: 📑 Defining safety claims: Specific risks (e.g., cybersecurity, misuse, system failures).🧠 Building arguments: Logical reasoning supporting safety claims… -- -- Exploring the evolving landscape of AI security, including threats, innovations, and strategies to safeguard AI systems and data.
3. Passion for solving problems, developing new solutions, innovation and experimentation Help Status About Careers Press Blog Privacy Terms Text to speech Teams
@secharvester
https://medium.com/ai-security-hub/understanding-the-safety-case-template-for-ai-systems-36bd99677478:
1. One approach is through a safety case: a structured, evidence-based argument aimed at demonstrating why the risk associated with a safety-critical system is acceptable.
2. It focuses on: 📑 Defining safety claims: Specific risks (e.g., cybersecurity, misuse, system failures).🧠 Building arguments: Logical reasoning supporting safety claims… -- -- Exploring the evolving landscape of AI security, including threats, innovations, and strategies to safeguard AI systems and data.
3. Passion for solving problems, developing new solutions, innovation and experimentation Help Status About Careers Press Blog Privacy Terms Text to speech Teams
@secharvester
Forwarded from Security Harvester
Unwrapping JavaScript Obfuscation: How LLMs Are Changing Cybercrime
https://medium.com/@stefan.kraam/unwrapping-javascript-obfuscation-how-llms-are-changing-cybercrime-3cd05c4a201e:
1. With a steaming cup of coffee in hand, I’ve decided to dive into one of the most fascinating (and troubling) trends in cybersecurity today: how large language models (LLMs) like GPT, LLaMA, and others are being weaponized to make JavaScript obfuscation more powerful than ever.
2. Traditional obfuscation relies on techniques like renaming variables to meaningless strings, encoding text in complex formats, or adding irrelevant lines of code.
3. Large Language Models — like OpenAI’s GPT, Meta’s LLaMA, Google’s PaLM, and Anthropic’s Claude — are designed to generate human-like text and code.
@secharvester
https://medium.com/@stefan.kraam/unwrapping-javascript-obfuscation-how-llms-are-changing-cybercrime-3cd05c4a201e:
1. With a steaming cup of coffee in hand, I’ve decided to dive into one of the most fascinating (and troubling) trends in cybersecurity today: how large language models (LLMs) like GPT, LLaMA, and others are being weaponized to make JavaScript obfuscation more powerful than ever.
2. Traditional obfuscation relies on techniques like renaming variables to meaningless strings, encoding text in complex formats, or adding irrelevant lines of code.
3. Large Language Models — like OpenAI’s GPT, Meta’s LLaMA, Google’s PaLM, and Anthropic’s Claude — are designed to generate human-like text and code.
@secharvester
Forwarded from Евгений Кокуйкин - Raft
Команда Yandex Cloud выпустила статью "Аспекты безопасности данных в Yandex Foundation Models". В ней описаны ключевые принципы обработки данных в нейросетях Яндекса: изоляция пользовательских данных, шифрование и соответствие ФЗ-152, анонимизация данных перед обучением и Stateless Inference. Обратите внимание, что по умолчанию промпты логируются для последующего обучения, однако эту опцию можно отключить в настройках.
Второй раздел статьи посвящён рекомендациям по созданию RAG-системы. В нём кратко описана архитектура вопросо-ответных систем и даны практические советы по настройке инфраструктуры в облаке. Для маскирования данных коллеги рекомендуют использовать сервисы обработки данных Data Proc или Data Transfer.
Интересно, что в статье пока отсутствуют упоминания о промпт-инъекциях и других атрибутах популярных AI Security фреймворков. Документ фокусируется исключительно на аспектах работы с данными.
Если вы собираетесь строить решения на YandexGPT, рекомендую чат, где вы можете напрямую пообщаться с разработчиками из Клауда и получить помощь по вашим вопросам.
Это была последняя статья в уходящем 2024 году. Дорогие друзья, коллеги и читатели канала, поздравляю вас с наступающим Новым годом! Пусть новые ИИ-продукты помогают быть эффективнее, забирают рутину и дарят нам больше времени для себя и близких 🎄.
Второй раздел статьи посвящён рекомендациям по созданию RAG-системы. В нём кратко описана архитектура вопросо-ответных систем и даны практические советы по настройке инфраструктуры в облаке. Для маскирования данных коллеги рекомендуют использовать сервисы обработки данных Data Proc или Data Transfer.
Интересно, что в статье пока отсутствуют упоминания о промпт-инъекциях и других атрибутах популярных AI Security фреймворков. Документ фокусируется исключительно на аспектах работы с данными.
Если вы собираетесь строить решения на YandexGPT, рекомендую чат, где вы можете напрямую пообщаться с разработчиками из Клауда и получить помощь по вашим вопросам.
Это была последняя статья в уходящем 2024 году. Дорогие друзья, коллеги и читатели канала, поздравляю вас с наступающим Новым годом! Пусть новые ИИ-продукты помогают быть эффективнее, забирают рутину и дарят нам больше времени для себя и близких 🎄.
Forwarded from Анализ данных (Data analysis)
@data_analysis_ml
Please open Telegram to view this post
VIEW IN TELEGRAM
Forwarded from CyberSecurityTechnologies (-CST-)
intercode.pdf
978 KB
Forwarded from CyberSecurityTechnologies (-CST-)
#MLSecOps
1. Hacking AI Applications:
From 3D Printing to RCE
https://www.securityrunners.io/post/hacking-ai-applications
2. Security ProbLLMs in xAI's Grok:
A Deep Dive
https://embracethered.com/blog/posts/2024/security-probllms-in-xai-grok
1. Hacking AI Applications:
From 3D Printing to RCE
https://www.securityrunners.io/post/hacking-ai-applications
2. Security ProbLLMs in xAI's Grok:
A Deep Dive
https://embracethered.com/blog/posts/2024/security-probllms-in-xai-grok
Forwarded from CyberSecurityTechnologies (-CST-)
#Cloud_Security
1. ModeLeak: Privilege Escalation to LLM Model Exfiltration in Vertex AI
https://unit42.paloaltonetworks.com/privilege-escalation-llm-model-exfil-vertex-ai
2. Dirty DAG: New Vulnerabilities in Azure Data Factory’s Apache Airflow Integration
https://unit42.paloaltonetworks.com/azure-data-factory-apache-airflow-vulnerabilities
]-> Kubernetes Hardening Guide
]-> Automation and Hardening of Kubernetes Cluster
1. ModeLeak: Privilege Escalation to LLM Model Exfiltration in Vertex AI
https://unit42.paloaltonetworks.com/privilege-escalation-llm-model-exfil-vertex-ai
2. Dirty DAG: New Vulnerabilities in Azure Data Factory’s Apache Airflow Integration
https://unit42.paloaltonetworks.com/azure-data-factory-apache-airflow-vulnerabilities
]-> Kubernetes Hardening Guide
]-> Automation and Hardening of Kubernetes Cluster
Forwarded from Анализ данных (Data analysis)
This media is not supported in your browser
VIEW IN TELEGRAM
Хронология самых интересных ИИ релизов в 2024 году🔥
От Gemma до Llama 3.1 405B, от Sonnet 3.5 до o3 !
https://huggingface.co/spaces/reach-vb/2024-ai-timeline
@data_analysis_ml
От Gemma до Llama 3.1 405B, от Sonnet 3.5 до o3 !
https://huggingface.co/spaces/reach-vb/2024-ai-timeline
@data_analysis_ml
Forwarded from PWN AI (Artyom Semenov)
В OWASP TOP 10 для LLM, в новой редакции, категория атак на цепочку поставок переместилась с 5ой на 3ю позицию. Это в целом было ожидаемо, большинство используют готовые компоненты и изменить процесс разработки, сделав изначально всё своими руками - крайне сложно. Но полезных источников описывающих эту проблему с ссылками и ресурсами - было не так много. Можно было почитать референсы в OWASP, и казалось что всё.
Автор репозитория awesome-llm-supply-chain-security, Shenaow, решил собирать полезные материалы по этой теме, для того чтобы мы могли быстро оценить то, какие угрозы и проблемы касаемо цепочки поставок есть сейчас.
Понятное дело что этот ресурс можно использовать как для составления докладов, так и для того чтобы попробовать посмотреть примеры и кейсы атак на цепочку поставок, именно в контексте LLM. Но некоторые статьи я посмотрел сам и нашёл кое-что интересное.
Во первых - Large Language Model Supply Chain: A Research Agenda, там приведена потрясающая классификация того, какие компоненты могут быть подвержены атаке, в сравнении с обычным ПО. Это исчерпывающая статья. Она описывает проблемы с которыми приходится сталкиваться на разных этапах, а в дополнение ещё описаны проблемы для агентов. (рисунок 1,2). Также есть краткое описание мер для защиты.
Large Language Model Supply Chain: Open Problems From the Security Perspective, если в первой статье мы видели только классификацию - то в этой статье мы видим уже маппинг атак на обучающую инфраструктуру и компоненты. Это в какой-то степени модель того, какие риски может реализовать злоумышленник в обучающей инфраструктуре. (рисунок 3)
Из полезного я также отметил для себя то, что автор собирает доклады, где эта проблема освящается а также CVE, которые стали возможными именно из-за проблем со стороны.
Автор репозитория awesome-llm-supply-chain-security, Shenaow, решил собирать полезные материалы по этой теме, для того чтобы мы могли быстро оценить то, какие угрозы и проблемы касаемо цепочки поставок есть сейчас.
Понятное дело что этот ресурс можно использовать как для составления докладов, так и для того чтобы попробовать посмотреть примеры и кейсы атак на цепочку поставок, именно в контексте LLM. Но некоторые статьи я посмотрел сам и нашёл кое-что интересное.
Во первых - Large Language Model Supply Chain: A Research Agenda, там приведена потрясающая классификация того, какие компоненты могут быть подвержены атаке, в сравнении с обычным ПО. Это исчерпывающая статья. Она описывает проблемы с которыми приходится сталкиваться на разных этапах, а в дополнение ещё описаны проблемы для агентов. (рисунок 1,2). Также есть краткое описание мер для защиты.
Large Language Model Supply Chain: Open Problems From the Security Perspective, если в первой статье мы видели только классификацию - то в этой статье мы видим уже маппинг атак на обучающую инфраструктуру и компоненты. Это в какой-то степени модель того, какие риски может реализовать злоумышленник в обучающей инфраструктуре. (рисунок 3)
Из полезного я также отметил для себя то, что автор собирает доклады, где эта проблема освящается а также CVE, которые стали возможными именно из-за проблем со стороны.