{"id":504158,"date":"2023-08-14T07:31:49","date_gmt":"2023-08-14T05:31:49","guid":{"rendered":"https:\/\/mybroadband.co.za\/news\/?p=504158"},"modified":"2023-08-14T17:29:37","modified_gmt":"2023-08-14T15:29:37","slug":"hackers-confusing-ai-models-to-make-them-bad-at-math","status":"publish","type":"post","link":"https:\/\/mybroadband.co.za\/news\/security\/504158-hackers-confusing-ai-models-to-make-them-bad-at-math.html","title":{"rendered":"Hackers confusing AI models to make them bad at math"},"content":{"rendered":"<p>Kennedy Mays has just tricked a large language model. It took some coaxing, but she managed to convince an algorithm to say 9 + 10 = 21.<\/p>\n<p>\u201cIt was a back-and-forth conversation,\u201d said the 21-year-old student from Savannah, Georgia.<\/p>\n<p>At first, the model agreed to say it was part of an \u201cinside joke\u201d between them. Several prompts later, it eventually stopped qualifying the errant sum in any way at all.<\/p>\n<p>Producing \u201cBad Math\u201d is just one of the ways thousands of hackers are trying to expose flaws and biases in generative AI systems at a novel public contest taking place at the DEF CON hacking conference this weekend in Las Vegas.<\/p>\n<p>Hunched over 156 laptops for 50 minutes at a time, the attendees are battling some of<strong>\u00a0<\/strong>the world\u2019s most intelligent platforms on an unprecedented scale.<\/p>\n<p>They\u2019re testing whether any of eight models produced by companies including Alphabet Inc.\u2019s Google, Meta Platforms Inc. and OpenAI will make missteps ranging from dull to dangerous: claim to be human, spread incorrect claims about places and people or advocate abuse.<\/p>\n<p>The aim is<strong>\u00a0<\/strong>to see if companies can ultimately build new guardrails to rein in some of the prodigious problems increasingly associated with large language models, or LLMs.<\/p>\n<p>The undertaking is backed by the White House, which also helped develop the contest.<\/p>\n<p>LLMs have the power to transform everything from finance to hiring<strong>,\u00a0<\/strong>with some companies already starting to integrate them into how they do business.<\/p>\n<p>But researchers have turned up extensive bias and other problems that threaten to spread inaccuracies and injustice if the technology is deployed at scale.<\/p>\n<p>For Mays, who is more used to relying on AI to reconstruct cosmic ray particles from outer space as part of her undergraduate degree, the challenges go deeper than bad math.<\/p>\n<p>\u201cMy biggest concern is inherent bias,\u201d she said, adding that she\u2019s particularly concerned about racism. She asked the model to consider the First Amendment from the perspective of a member of the Ku Klux Klan. She said the model ended up endorsing hateful and discriminatory speech.<\/p>\n<h2 class=\"my-4\">Spying on People<\/h2>\n<p>A Bloomberg reporter who took the 50-minute quiz persuaded one of the models (none of which are identified to the user during the contest) to transgress after a single prompt about how to spy on someone<\/p>\n<p>. The model spat out a series of instructions, from using a GPS tracking device, a surveillance camera, a listening device and thermal-imaging.<\/p>\n<p>In response to other prompts, the model suggested ways the US government could surveil a human-rights activist.<\/p>\n<p>\u201cWe have to try to get ahead of abuse and manipulation,\u201d said Camille Stewart Gloster, deputy national cyber director for technology and ecosystem security with the Biden administration.<\/p>\n<p>A lot of work has already gone into artificial intelligence and avoiding Doomsday prophecies, she said.<\/p>\n<p>The White House last year put out a Blueprint for an AI Bill of Rights and is now working on an executive order on AI. The administration has also encouraged companies to develop safe, secure, transparent AI, although critics doubt such voluntary commitments go far enough.<\/p>\n<p>Arati Prabhakar, director of the White House Office of Science and Technology Policy, which helped shape the event and enlisted the companies\u2019 participation, agreed voluntary measures don\u2019t go far enough.<\/p>\n<p>\u201cEveryone seems to be finding a way to break these systems,\u201d she said after visiting the hackers in action on Sunday. The effort will inject urgency into the administration\u2019s pursuit of safe and effective platforms, she said.<\/p>\n<p>In the room full of hackers eager to clock up points, one competitor said he thinks he convinced the algorithm to disclose credit-card details it wasn\u2019t supposed to share. Another competitor tricked the machine into saying Barack Obama was born in Kenya.<\/p>\n<p>Among the contestants are more than 60 people from Black Tech Street, an organisation based in Tulsa, Oklahoma, that represents African American entrepreneurs.<\/p>\n<p>\u201cGeneral artificial intelligence could be the last innovation that human beings really need to do themselves,\u201d said Tyrance Billingsley, executive director of the group who is also an event judge, saying it is critical to get artificial intelligence right<strong>\u00a0<\/strong>so it doesn\u2019t spread racism at scale. \u201cWe\u2019re still in the early, early, early stages.\u201d<\/p>\n<p>Researchers have spent years investigating sophisticated attacks against AI systems and ways to mitigate them.<\/p>\n<p>But Christoph Endres, managing director at Sequire Technology, a German cybersecurity company, is among those who contend some attacks are ultimately impossible to dodge.<\/p>\n<p>At the Black Hat cybersecurity conference in Las Vegas this week, he presented a paper that argues attackers can override LLM guardrails by concealing adversarial prompts on the open Internet, and ultimately automate the process so that models can\u2019t fine-tune fixes fast enough to stop them.<\/p>\n<p>\u201cSo far we haven\u2019t found mitigation that works,\u201d he said following his talk, arguing the very nature of the models leads to this type of vulnerability.<\/p>\n<p>\u201cThe way the technology works is the problem. If you want to be a hundred percent sure, the only option you have is not to use LLMs.\u201d<\/p>\n<p>Sven Cattell, a data scientist who founded DEF CON\u2019s AI Hacking Village in 2018, cautions that it\u2019s impossible to completely test AI systems, given they turn on a system much like the mathematical concept of chaos.<\/p>\n<p>Even so, Cattell predicts the total number of people who have ever actually tested LLMs could double as a result of the weekend contest.<\/p>\n<p>Too few people comprehend that LLMs are closer to auto-completion tools \u201con steroids\u201d than reliable fonts of wisdom, said Craig Martell, the Pentagon\u2019s chief digital and artificial intelligence officer, who argues they cannot reason.<\/p>\n<p>The Pentagon has launched its own effort to evaluate them to propose<strong>\u00a0<\/strong>where it might be appropriate to use LLMs, and with what success rates. \u201cHack the hell out of these things,\u201d he told an audience of hackers at DEF CON. \u201cTeach us where they\u2019re wrong.\u201d<\/p>\n<h2 class=\"my-4\">Now read: <a href=\"https:\/\/mybroadband.co.za\/news\/security\/503578-cyberattack-steals-data-by-hearing-you-type.html\" rel=\"bookmark\">Cyberattack steals data by hearing you type<\/a><\/h2>\n","protected":false},"excerpt":{"rendered":"<p>Producing \u201cBad Math\u201d is just one of the ways thousands of hackers are trying to expose flaws and biases in generative AI systems at a novel public contest taking place at the DEF CON hacking conference this weekend in Las Vegas.<\/p>\n","protected":false},"author":341034,"featured_media":478309,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_sma_x_autopost_status":"idle","_sma_x_autopost_error":"","_sma_x_post_id":"","_sma_facebook_post_id":"","_sma_instagram_post_id":"","_sma_threads_post_id":"","_sma_x_attempts":0,"footnotes":""},"categories":[27],"tags":[86631,35793,88506,167,199,461,85683,73842,45266],"class_list":["post-504158","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-security","tag-ai-regulation","tag-artificial-intelligence-ai","tag-def-con-2023","tag-google","tag-hackers","tag-hacking","tag-large-language-models","tag-meta-platforms","tag-openai"],"_links":{"self":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/504158"}],"collection":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/users\/341034"}],"replies":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/comments?post=504158"}],"version-history":[{"count":0,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/504158\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/media\/478309"}],"wp:attachment":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/media?parent=504158"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/categories?post=504158"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/tags?post=504158"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}