
Researchers have spotted two machine learning (ML) models containing malicious code on Hugging Face Hub, a popular online repository.

Malicious ML models found on Hugging Face Hub
Researchers have spotted two machine learning (ML) models containing malicious code on Hugging Face Hub, a popular online repository.
cross-posted from: https://infosec.pub/post/23608855
AI Risk Repository
A comprehensive living database of over 1600 AI risks categorized by their cause and risk domain
For seven months, 'ShadowRay' gave attackers access to thousands of AI workloads, computing power, credentials, keys and tokens.
AI hallucinates software packages and devs download them – even if potentially poisoned with malware
Simply look out for libraries imagined by ML and make them real, with actual malicious code. No wait, don't do that
Intelligent systems demand more than just repurposed cybersecurity tools
Today's safety guardrails won't catch these backdoors
NIST: If someone's trying to sell you some secure AI, it's snake oil
You really think someone would do that? Go on the internet and tell lies?
Boffins devise 'universal backdoor' for image models to cause AI hallucinations
Data poisoning appears open to all
Are Local LLMs Useful in Incident Response?, Author: Tom Webb
From AI to just plain aaaiiiee!
New AI Beats DeepMind’s AlphaGo Variants 97% Of The Time!
Click to view this content.
Why established cyber security principles are still important when developing or implementing machine learning models.
GitHub - google/model-transparency
Supply chain security for ML. Contribute to sigstore/model-transparency development by creating an account on GitHub.
disinformation videos on AI ?
Hi all,
Had a small chat on #AI with somebody yesterday, when this video came up: "10 Things They're NOT Telling You About The New AI" (*)
What strikes me the most on this video is not the message, but the way it is brought. It has all the prints of #disinformation over it, .. especially as it is coming from a youtube-channel that does not even post a name or a person.
Does anybody know this organisation and who is behind it?
Is this "you are all going to lose your job of AI and that's all due to " message new? What is the goal behind this?
(Sorry to post this message here. I have been looking for a lenny/kbin forum on disinformation, but did not find it, so I guess it is most relevant here)
OWASP Top 10 for LLMs (v1.0)
Aims to educate developers, designers, architects, managers, and organizations about the potential security risks when deploying and managing Large Language Models (LLMs)