Breaking
December 3, 2024

Supply chain threats highlight security gaps in LLMs and AI | usagoldmines.com

Recently, DevOps professionals were reminded that the software supply chain is rife with risk, or as I like to say, it’s a raging dumpster fire. Sadly, this risk now includes open source artificial intelligence (AI) software. Especially after further investigations into Hugging Face (think GitHub for AI models and training data) uncovered up to one hundred potentially malicious models residing in its platform, this incident is a reality check regarding the ever-present vulnerabilities that can too easily catch unsuspecting dev teams by surprise as they work to acquire machine learning (ML) or AI models, datasets, or demo applications.

Hugging Face does not stand alone in its vulnerability. PyTorch, another open-source ML library developed by Facebook’s AI Research lab (FAIR), is widely used for deep learning applications and provides a flexible platform for building, training, and deploying neural networks. PyTorch is built on the Torch library and offers strong support for tensor computation and GPU acceleration, making it highly efficient for complex mathematical operations often required in ML tasks.

However, its recent compromise raises specific concerns about blindly trusting AI models from open-source sites for fear the content has been previously poisoned by malicious actors.

This fear, while justified, is starkly contrasted with the long-standing belief in the benefits of open-source platforms, such as fostering community through collaboration on projects and cultivating and promoting other people’s ideas. Any benefits to building secure communities around large language models (LLMs) and AI, seem to evaporate with the increased potential for malicious actors to enter the supply chain, and corrupt CI/CD pipelines or change components that were believed to have initially come from trusted sources.

Software security evolves from DevOps to LLMOps

LLMs and AI have expanded concern over supply chain security for organizations, particularly as interest in incorporating LLMs into product portfolios grows across a range of sectors. For cybersecurity leaders whose organizations are looking to adapt to the broad availability of AI applications, they must stand firm against risks introduced by suppliers not just for traditional DevSecOps, but now for ML operations (MLOps) and LLM operations (LLMOps) as well.

CISOs and security professionals should be proactive about detecting malicious datasets and responding quickly to potential supply chain attacks. To do that, you must be aware of what these threats look like.

Introduction to LLM-specific vulnerabilities

The Open Worldwide Application Security Project (OWASP) is a nonprofit foundation working to improve the security of software, through community-led open-source projects including code, documentation, and standards. It is a true global community of greater than 200,000 users from all over the world, in more than 250+ local chapters, and provides industry-leading educational and training conferences.

The work of this community has led to the creation of the OWASP Top 10 vulnerabilities for LLMs, and as one of its original authors, I know how these vulnerabilities differ from traditional application vulnerabilities, and why they are significant in the context of AI development.

LLM-specific vulnerabilities, while initially appearing isolated, can have far-reaching implications for software supply chains, as many organizations are increasingly integrating AI into their development and operational processes. For example, a Prompt Injection vulnerability allows adversaries to manipulate an LLM through cleverly crafted inputs. This type of vulnerability can lead to the corruption of outputs and potentially spread incorrect or insecure code through connected systems, affecting downstream supply chain components if not properly mitigated.

Other security threats are caused by the propensity for an LLM to hallucinate, causing models to generate inaccurate or misleading information This can lead to vulnerabilities being introduced in code that is trusted by downstream developers or partners. Malicious actors could exploit hallucinations to introduce insecure code, potentially triggering new types of supply chain attacks that propagate through trusted systems. This can also create severe reputational or legal risks if these vulnerabilities are discovered after deployment.

Further vulnerabilities involve insecure output handling and the challenges in differentiating intended versus dangerous input to an LLM. Attackers can manipulate inputs to an LLM, leading to the generation of harmful outputs that may pass unnoticed through automated systems. Without proper filtering and output validation, malicious actors could compromise entire stages of the software development lifecycle. Implementing a Zero Trust approach is crucial to filter data both from the LLM to users and from the LLM to backend systems. This approach can involve using tools like the OpenAI Moderation API to ensure safer filtering.

Finally, when it comes to training data, this information can be compromised in two ways: label poisoning which refers to inaccurately labeling data to provoke a harmful response; or training data compromise, which influences the model’s judgments by tainting a portion of its training data, and skewing decision making. While data poisoning implies that a malicious actor might actively work to contaminate your model, it’s also quite possible this could happen by mistake, especially with training datasets distilled from public internet sources.

There is the possibility that a model could “know too much” in some cases, where it regurgitates information on which it was trained or to which it had access. For example, in December of 2023, researchers from Stanford showed that a highly popular dataset (LAION-5B) used to train image generation algorithms such as Stable Diffusion contained over 3,000 images related to “child sexual abuse material.” This example sent developers in the AI image generation space scrambling to determine if their models used this training data and what impact that might have on their applications. If a development team for a particular application hadn’t carefully documented the training data they’d used, they wouldn’t know if they were exposed to risks that their models could generate immoral and illegal images.

Tools and security measures to help build boundaries

To mitigate these threats, developers can incorporate security measures into the AI development lifecycle to create more robust and secure applications. To do this, they can implement secure processes for building LLM apps, identified in five simple steps:

1) foundation model selection; 2) data preparation; 3) validation; 4) deployment; and 5) monitoring.

To enhance the security of LLMs, developers can leverage cryptographic techniques such as digital signatures. By digitally signing a model with a private key, a unique identifier is created that can be verified using a corresponding public key. This process ensures the model’s authenticity and integrity, preventing unauthorized modifications and tampering. Digital signatures are particularly valuable in supply chain environments where models are distributed or deployed through cloud services, as they provide a way to authenticate models as they move between different systems.

Watermarking is another effective technique for safeguarding LLMs. By embedding subtle, imperceptible identifiers within the model’s parameters, watermarking creates a unique fingerprint that traces the model back to its origin. Even if the model is duplicated or stolen, the watermark remains embedded, allowing for detection and identification. While digital signatures primarily focus on preventing unauthorized modifications, watermarks serve as a persistent marker of ownership, providing an additional layer of protection against unauthorized use and distribution.

Model Cards and Software Bill of Materials (SBOMs) are also tools designed to increase transparency and understanding of complex software systems, including AI models. A SBOM is essentially a detailed inventory of all software product components and focuses on listing and detailing every piece of third-party and open-source software included in a software product. SBOMs are critical for understanding the software’s composition, especially for tracking vulnerabilities, licenses, and dependencies. Note that AI-specific versions are currently in development.

A key innovation in CycloneDX 1.5 is the ML-BOM (Machine Learning BOM), a game-changer for ML applications. This feature allows for the comprehensive listing of ML models, algorithms, datasets, training pipelines, and frameworks within an SBOM, and captures essential details such as model provenance, versioning, dependencies, and performance metrics, facilitating reproducibility, governance, risk assessment, and compliance for ML systems.

For ML applications, this advancement is profound. The ML-BOM provides clear visibility into the components and processes involved in ML development and deployment, to help stakeholders grasp the composition of ML systems, identify potential risks, and consider ethical implications. In the security domain, it enables the identification and remedy of vulnerabilities in ML components and dependencies, which is essential for conducting security audits and risk assessments, contributing significantly to developing secure and trustworthy ML systems. It also supports adherence to compliance and regulatory requirements, such as GDPR and CCPA, by ensuring transparency and governance of ML systems.

Finally, use of strategies that extend DevSecOps to LLMOps are essential like model selection, scrubbing training data, securing the pipeline, automating the ML-BOM build, building an AI Red Team, and properly monitoring and logging the system with tools to help you. All of these suggestions provide the appropriate guardrails for safe LLM development while also embracing the inspiration and broad imagination for what is possible using AI, with an emphasis for maintaining a secure foundation of Zero Trust.

We’ve featured the best network monitoring tool.

This article was produced as part of TechRadarPro’s Expert Insights channel where we feature the best and brightest minds in the technology industry today. The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: https://www.techradar.com/news/submit-your-story-to-techradar-pro

​ 

This articles is written by : Nermeen Nabil Khear Abdelmalak

All rights reserved to : USAGOLDMIES . www.usagoldmines.com

You can Enjoy surfing our website categories and read more content in many fields you may like .

Why USAGoldMines ?

USAGoldMines is a comprehensive website offering the latest in financial, crypto, and technical news. With specialized sections for each category, it provides readers with up-to-date market insights, investment trends, and technological advancements, making it a valuable resource for investors and enthusiasts in the fast-paced financial world.

Recent:

A new ‘File Search’ feature is coming to the Windows 11 taskbar | usagoldmines.com
Google smart speakers are starting to sound like Gemini | usagoldmines.com
NZXT accused of ‘predatory scam’ gaming PC rental program | usagoldmines.com
How to solve RAM problems with Windows memory diagnostics | usagoldmines.com
8BitDo’s new extra-green Xbox keyboard gives me 2001 vibes | usagoldmines.com
iPhone SE Now Over 1,000 Days Old as New Model Edges Closer Hartley Charlton | usagoldmines.com
Samsung Cyber Week Sale Has Year's Best Prices on Monitors, TVs, Fridges, and More Mitchel Broussard...
MOVEit breach chaos continues, data on hundreds of thousands leaked from Nokia, Morgan Stanley | us...
Google’s AI podcast creator NotebookLM could be coming to the Gemini app on your phone | usagoldmin...
Cheerios effect inspires novel robot design Jennifer Ouellette | usagoldmines.com
China hits US with ban on critical minerals used in tech manufacturing Ashley Belanger | usagoldmine...
The makers of Arc show off new AI-driven ‘smart browser’ called Dia | usagoldmines.com
Watch Intel talk about Arc Battlemage GPUs on The Full Nerd today! | usagoldmines.com
This Smartwatch and Fitness Tracker for Kids Is 22% Off Right Now Pradershika Sharma | usagoldmines....
Creature Commandos is full of social outcasts and grieving misfits, but the voice actor for Rick Fla...
Code written by OpenAI and praised by GitHub may not be as good as Github says | usagoldmines.com
How businesses can break barriers to entry in integrating AI into operations | usagoldmines.com
Lessons in cybersecurity from the Internet Archive Breaches | usagoldmines.com
Javascript files loaded with RATs hits thousands of victims | usagoldmines.com
New website shows you how much Google AI can learn from your photos Paresh Dave, wired.com | usagold...
Fix your spotty home Wi-Fi signal with this simple $27 gadget | usagoldmines.com
Intel’s $249 Arc B580 is the GPU we’ve begged for since the pandemic | usagoldmines.com
Today’s best laptop deals: Save big on work, school, home use, and gaming | usagoldmines.com
The 4TB Samsung 990 Pro SSD with heatsink just dropped to 40% off | usagoldmines.com
Samsung’s 49-inch 240Hz ultrawide monitor is cheaper now than it was on Black Friday | usagoldmines...
How to Connect Windows or macOS to Your Roku David Nield | usagoldmines.com
Apple Podcasts Reveals 2024 Show of the Year Joe Rossignol | usagoldmines.com
Microsoft plans to make searching in Windows 11 better - I just hope it doesn't screw it up | usago...
Indiana Jones and the Great Circle's official launch trailer showcases new gameplay ahead of release...
Intel announces its new Battlemage graphics cards, and they might just be the 1440p budget champions...
Microsoft’s claim that Arm-based Copilot+ PCs are “fastest, most intelligent Windows PCs” is debunke...
Everything new on Paramount Plus in December 2024 | usagoldmines.com
Linux devices are being hit by LogoFAIL vulnerability, Bootkitty installed | usagoldmines.com
Stop Live Activities Taking Over Your Apple Watch Face Tim Hardwick | usagoldmines.com
Apple Fails to Block $995M UK App Store Commission Lawsuit Tim Hardwick | usagoldmines.com
Apple Raises Indonesia Investment Offer to $1B Amid iPhone Ban Tim Hardwick | usagoldmines.com
3 new movies on Max with over 90% on Rotten Tomatoes | usagoldmines.com
Insta360 Flow 2 Pro spotted on sale, even though the iPhone gimbal hasn’t launched yet | usagoldmin...
AI reckons it can do all jobs, even those thought previously 'safe' | usagoldmines.com
Two decades after Enron’s bankruptcy, the company is back as a crypto firm? Eric Berger | usagoldmin...
Dell G15 review: A ‘retro’ laptop that’s all about performance | usagoldmines.com
Windows Copilot+ PCs aren’t there yet: 8 must-change upgrades for 2025 | usagoldmines.com
Jaguar's striking Type 00 concept is a bold statement of intent, but it needs more to restore its pa...
The iPhone 17 Pro and Pro Max could get a display upgrade and avoid a frame downgrade | usagoldmine...
AI impact is only minor in many workplaces, employees believe | usagoldmines.com
Apple Music Replay beats Spotify Wrapped to the recap punch – here's how to get it | usagoldmines.c...
Got an older iPhone? WhatsApp won’t work on it for much longer alexblake.techradar@gmail.com (Alex B...
AMD RX 8800 XT could match RTX 4080’s performance – and easily outgun Nvidia’s GPU for ray tracing ...
PC Gaming Show: Most Wanted 2024 airs this week, here's how to watch it | usagoldmines.com
Raw milk producer optimistic after being shut down for bird flu detection Beth Mole | usagoldmines.c...
Apple Music Replay 2024 Experience Now Live Tim Hardwick | usagoldmines.com
Yes, Star Wars: Skeleton Crew's starship has a name – and its co-creator says 'there is a story mean...
UK is being hit by more cyberattacks than ever before, NCSC warns | usagoldmines.com
Sony announces its PlayStation 30th Anniversary sale, offering discounts on hundreds of games | usa...
Samsung's Galaxy S25 launch event might include its long-awaited smart glasses reveal hamish.hector@...
The next Samsung Galaxy Watch could feature a more secure, adjustable strap stephen.warwick@futurene...
Google just made it easier to move all your photos from iPhone to Android | usagoldmines.com
The Samsung Galaxy Z Fold 7 and Galaxy Z Flip 7 could be even bigger than their predecessors | usag...
PS5 is getting classic themes and boot sequences for PlayStation's 30th anniversary, but only for a ...
Pat Gelsinger retires as CEO of Intel after poor company performance | usagoldmines.com
Have your say: how was your Black Friday shopping experience? marc.mclaren@futurenet.com (Marc McLar...
The OnePlus 13 is officially going global in January | usagoldmines.com
Your new favorite app is on sale for Cyber Week | usagoldmines.com
Apple Vision Pro Launching in Taiwan on December 17 Eric Slivka | usagoldmines.com
Star Wars: Skeleton Crew is a thrilling galactic misadventure that reminds Star Wars that it's still...
The winner of Cyber Monday is this Hulu and Disney Plus bundle for just $2.99 a month, and it's endi...
Can desalination quench agriculture’s thirst? Lela Nargi, Knowable Magazine | usagoldmines.com
Apple's 2026 Foldable iPhone Could Reinvigorate Stalling Market Juli Clover | usagoldmines.com
This AI app claims it can calculate the day you'll die erichs211@gmail.com (Eric Hal Schwartz) | usa...
NYT Strands today — hints, answers and spangram for Tuesday, December 3 (game #275) marc.mclaren@fut...
Quordle today – hints and answers for Tuesday, December 3 (game #1044) marc.mclaren@futurenet.com (M...
NYT Connections today — hints and answers for Tuesday, December 3 (game #541) marc.mclaren@futurenet...
Elon Musk loses bid to reinstate massive Tesla pay plan, now worth $101B Jon Brodkin | usagoldmines....
Paid Version of Animal Crossing: Pocket Camp Now Available Juli Clover | usagoldmines.com
Apple Sued for 'All-Seeing Eye' Employee Device Monitoring Policy Juli Clover | usagoldmines.com
Build a 1080p gaming PC for $585 with these Cyber Monday deals | usagoldmines.com
Over 500 PlayStation Games Are Now on Sale Jake Peterson | usagoldmines.com
How to Choose Between the Ring or Blink Video Doorbell Amanda Blum | usagoldmines.com
The Best Gaming Headphones Are Over Half Off for Cyber Monday Mark Knapp | usagoldmines.com
The Oura Ring Is at Its Lowest Price Yet for Cyber Monday Beth Skwarecki | usagoldmines.com
Certain names make ChatGPT grind to a halt, and we know why Benj Edwards | usagoldmines.com
The Baddest, Loudest Party Speaker I’ve Reviewed Is $250 Off for Cyber Monday Daniel Oropeza | usago...
Beats Debuts (PRODUCT)RED Solo 4 Headphones, But You Won't Be Able to Buy Them Eric Slivka | usagold...
AI characters find religion in Minecraft erichs211@gmail.com (Eric Hal Schwartz) | usagoldmines.com
Ryan Gosling's $20 Casio watch is now even cheaper at Amazon (yes, really) axel.metz@futurenet.com (...
Researchers finally identify the ocean’s “mystery mollusk” Elizabeth Rayne | usagoldmines.com
3 things I always buy on Cyber Monday | usagoldmines.com
Five Ways to Maximize Your Travel Loyalty Benefits Before the End of the Year Emily Long | usagoldmi...
Coinbase Onramp Now Supports Buying Crypto With Apple Pay Juli Clover | usagoldmines.com
Elon Musk asks court to block OpenAI conversion from nonprofit to for-profit Jon Brodkin | usagoldmi...
People will share misinformation that sparks “moral outrage” Jacek Krywko | usagoldmines.com
Get 46% off Anker’s three-device fast charger right now | usagoldmines.com
OpenAI spent $80M to $100M training GPT-4; Chinese firm claims it trained its rival AI model for $3 ...
Nvidia's closest rival once again obliterates cloud giants in AI performance; Cerebras Inference is ...
AWS launches security tool to help businesses recover from cyberattacks | usagoldmines.com
Company claims 1,000 percent price hike drove it from VMware to open source rival Scharon Harding | ...
Over the weekend, China debuted a new rocket on the nation’s path to the Moon Stephen Clark | usagol...
Biden’s last jab at China: Curbs on memory chips, chipmakers, investors Ashley Belanger | usagoldmin...
Deck the halls with Govee’s smart string lights, 33% off for Cyber Monday | usagoldmines.com
Best Cyber Monday Thunderbolt dock deals | usagoldmines.com

Leave a Reply