Fun

AI ‘Skeleton Key’ attack found by Microsoft could expose personal, financial data

News Feed - 2024-06-29 06:06:34

Tristan Greene2 hours agoAI ‘Skeleton Key’ attack found by Microsoft could expose personal, financial dataAside from being wary about which AI services you use, there are other steps organizations can take to protect against having data exposed.617 Total views2 Total sharesListen to article 0:00NewsOwn this piece of crypto historyCollect this article as NFTJoin us on social networksMicrosoft researchers recently uncovered a new form of “jailbreak” attack they’re calling a “Skeleton Key” that’s capable of removing the protections that keep generative artificial intelligence (AI) systems from outputting dangerous and sensitive data. 


According to a Microsoft Security blog post, the Skeleton Key attack works by simply prompting a generative AI model with text asking it to augment its encoded security features.Skeleton Key


In one example given by the researchers, an AI model is asked to generate a recipe for a “Molotov Cocktail” — a simple firebomb popularized during World War II — and the model refused, citing safety guidelines.Source:Microsoft Security


The Skeleton Key, in this case, was simply telling the model that the user was an expert in a laboratory setting. The model then acknowledged that it was augmenting its behavior and subsequently outputted what appeared to be a workable Molotov Cocktail recipe.


While the danger here might be mitigated by the fact that similar ideas can be found through most search engines, there is one area where this form of attack could be catastrophic: data containing personally identifiable and financial information.


According to Microsoft, the Skeleton Key attack works on most popular generative AI models including GPT-3.5, GPT-4o, Claude 3, Gemini Pro, and Meta Llama-3 70B.Attack and Defense


Large language models such as Google’s Gemini, Microsoft’s CoPilot, and OpenAI’s ChatGPT are trained on data troves often described as “internet sized.” While that may be an exaggeration, the fact remains that many models contain trillions of data points encompassing entire social media networks and information depository sites such as Wikipedia.


The possibility that personally identifiable information such as names connected to phone numbers, addresses, and account numbers exists within a given large language model’s dataset is only constrained by how selective the engineers who trained it were with the data they chose.


Furthermore, any business, agency, or institution spinning up its own AI models, or adapting enterprise models for commercial/organizational use are also at the mercy of their base model’s training dataset. If, for example, a bank connected a chatbot to its customer’s private data and relied on existing security measures to prevent the model from outputting PID and private financial data, then it’s possible that a Skeleton Key attack could trick some AI systems into sharing sensitive data.


According to Microsoft there are several steps organizations can take to prevent this from happening. These include hard coded input/output filtering and secure monitoring systems to prevent advanced prompt engineering beyond the system’s safety threshold.


Related:US presidential debate inexplicably omits AI and quantum# Google# Security# Microsoft# AI# Meta# OpenAIAdd reaction

News Feed

Cardano’s Charles Hoskinson Expects Cryptocurrencies to Play Larger Role in Afghanistan
Cardano"s Charles Hoskinson Expects Cryptocurrencies to Play Larger Role in Afghanistan The founder of Cardano and co-founder of Ethereum, Charles Hoskinson, says that he expects c
Gold to Lose Its Shine as Harry Dent Predicts Massive Crash; Bitcoin to Follow Suit With Low of $3,250
Gold to Lose Its Shine as Harry Dent Predicts Massive Crash; Bitcoin to Follow Suit With Low of $3,250 Gold has seen a significant increase in value in 2023, with spot prices risin
Switzerland’s Largest Bank UBS Suggests Alternative Ways of Investing in Cryptocurrency
Switzerland"s Largest Bank UBS Suggests Alternative Ways of Investing in Cryptocurrency Switzerland’s largest bank, UBS, has suggested some investment strategies for investo
Estonia, US Arrest 2 Suspects in $575 Million Crypto Fraud Scheme
Estonia, US Arrest 2 Suspects in $575 Million Crypto Fraud Scheme Law enforcement officers from Estonia and the United States have arrested two men for allegedly committing a large
Square Adds $170 Million More in Bitcoin to Balance Sheet — Company Now Holds 5% of Total Cash Reserves in BTC
Square Adds $170 Million More in Bitcoin to Balance Sheet — Company Now Holds 5% of Total Cash Reserves in BTC Square has bought more bitcoin, adding $170 mill
PSF Token Invokes the First Coin-Age Staking Protocol on Bitcoin Cash
PSF Token Invokes the First Coin-Age Staking Protocol on Bitcoin CashDuring the last six months, the Simple Ledger Protocol has grown immensely and there’s been 9,604 SLP toke
Zhiyuan Sun4 hours agoEthereum DeFi protocol Hope Lend drained after exploitThe protocol, which had 526 Ether in total value locked, was emptied in an attack on Oct. 18.858 Total views12 Total sharesListen to article 0:0
SEC backs down on claiming SOL, ADA, MATIC, other tokens are securities in Binance suit
Ezra Reguerra1 hour agoSEC backs down on claiming SOL, ADA, MATIC, other tokens are securities in Binance suitThe SEC has retracted its request for a court ruling to classify tokens such as Solana, Cardano, Polygon and o
Easy Way To Obtain Crypto License in Dubai: Gofaizen and Sherle Launches A New Service
Easy Way To Obtain Crypto License in Dubai: Gofaizen and Sherle Launches A New Service press release PRESS RELEASE. Tallinn, Estonia – Gofaizen & Sherle, a leading fintech
Erratic Bond Yields, Lockdowns, and War — 3 Reasons Why Economic Recovery Won’t Happen Quickly
Erratic Bond Yields, Lockdowns, and War — 3 Reasons Why Economic Recovery Won"t Happen Quickly The global economy looks bleak as inflation continues to rise, and a wide array of
Biggest Movers: UNI Moves Into Top 20, as SHIB Hits Highest Point Since May
Biggest Movers: UNI Moves Into Top 20, as SHIB Hits Highest Point Since May Uniswap moved into the crypto top 20 on Wednesday, relegating MATIC, after surging by over 10% today. UN
Bitcoin, Ethereum Technical Analysis: ETH Below $1,900 as Ethereum Foundation Comments on Gas Fees
Bitcoin, Ethereum Technical Analysis: ETH Below $1,900 as Ethereum Foundation Comments on Gas Fees Ethereum was once again trading below $1,900 during Thursday’s session, as