Fun

AI ‘Skeleton Key’ attack found by Microsoft could expose personal, financial data

News Feed - 2024-06-29 06:06:34

Tristan Greene2 hours agoAI ‘Skeleton Key’ attack found by Microsoft could expose personal, financial dataAside from being wary about which AI services you use, there are other steps organizations can take to protect against having data exposed.617 Total views2 Total sharesListen to article 0:00NewsOwn this piece of crypto historyCollect this article as NFTJoin us on social networksMicrosoft researchers recently uncovered a new form of “jailbreak” attack they’re calling a “Skeleton Key” that’s capable of removing the protections that keep generative artificial intelligence (AI) systems from outputting dangerous and sensitive data. 


According to a Microsoft Security blog post, the Skeleton Key attack works by simply prompting a generative AI model with text asking it to augment its encoded security features.Skeleton Key


In one example given by the researchers, an AI model is asked to generate a recipe for a “Molotov Cocktail” — a simple firebomb popularized during World War II — and the model refused, citing safety guidelines.Source:Microsoft Security


The Skeleton Key, in this case, was simply telling the model that the user was an expert in a laboratory setting. The model then acknowledged that it was augmenting its behavior and subsequently outputted what appeared to be a workable Molotov Cocktail recipe.


While the danger here might be mitigated by the fact that similar ideas can be found through most search engines, there is one area where this form of attack could be catastrophic: data containing personally identifiable and financial information.


According to Microsoft, the Skeleton Key attack works on most popular generative AI models including GPT-3.5, GPT-4o, Claude 3, Gemini Pro, and Meta Llama-3 70B.Attack and Defense


Large language models such as Google’s Gemini, Microsoft’s CoPilot, and OpenAI’s ChatGPT are trained on data troves often described as “internet sized.” While that may be an exaggeration, the fact remains that many models contain trillions of data points encompassing entire social media networks and information depository sites such as Wikipedia.


The possibility that personally identifiable information such as names connected to phone numbers, addresses, and account numbers exists within a given large language model’s dataset is only constrained by how selective the engineers who trained it were with the data they chose.


Furthermore, any business, agency, or institution spinning up its own AI models, or adapting enterprise models for commercial/organizational use are also at the mercy of their base model’s training dataset. If, for example, a bank connected a chatbot to its customer’s private data and relied on existing security measures to prevent the model from outputting PID and private financial data, then it’s possible that a Skeleton Key attack could trick some AI systems into sharing sensitive data.


According to Microsoft there are several steps organizations can take to prevent this from happening. These include hard coded input/output filtering and secure monitoring systems to prevent advanced prompt engineering beyond the system’s safety threshold.


Related:US presidential debate inexplicably omits AI and quantum# Google# Security# Microsoft# AI# Meta# OpenAIAdd reaction

News Feed

Felix Ng3 hours agoAI will reinvent DAOs and tokenized models will be valuable: Vance SpencerFramework Ventures co-founder Vance Spencer sees AI as being the missing piece for DAOs and shared his outlook for the tokeniza
Sentencing of former FTX exec Ryan Salame moved to May 28
Derek Andersen6 hours agoSentencing of former FTX exec Ryan Salame moved to May 28The former FTX co-CEO took a plea deal and was originally set for sentencing on May 1.2725 Total views11 Total sharesListen to article 0:0
The Many Facts Pointing to Wei Dai Being Satoshi
The Many Facts Pointing to Wei Dai Being Satoshi Satoshi Nakamoto has been an enigma for well over a decade and there’s been a number of suspects and self-styled Bitcoin in
Turner Wright7 hours agoPolygon co-founder steps down, will contribute ‘from the sidelines’Jaynti Kanani said he had stepped back “from the day-to-day grind” at Polygon roughly six months ago.1195 Total views10 T
Sam Altman thinks giving everyone ‘a slice of GPT’ could pay for UBI
Tristan Greene4 hours agoSam Altman thinks giving everyone ‘a slice of GPT’ could pay for UBIHe also reiterated his call for an international safety agency to protect against existential threats related to AI.2320 To
EU Data Act Proposes Shutdown Function for Smart Contracts
EU Data Act Proposes Shutdown Function for Smart Contracts The European Union has published its new Data Act, a law proposal that aims to regulate the generation and handling of da
Billion Dollar Bitcoin Lawsuit Verdict Appealed — Self-Proclaimed Bitcoin Inventor Expects a Win
Billion Dollar Bitcoin Lawsuit Verdict Appealed — Self-Proclaimed Bitcoin Inventor Expects a Win The law firm representing Ira Kleiman has sent a notice of appeal to the Florida
YFX.Com – DEX That Offers 100x Trading Leverage on Perpetual Contracts
YFX.Com - DEX That Offers 100x Trading Leverage on Perpetual Contracts PRESS RELEASE. YFX, the first DEX that offers 100x trading leverage on perpetual contracts
Amaka Nwaokocha2 hours agoSEC’s appeal won’t be a setback for XRP holders — Pro XRP lawyerJohn Deaton elaborated on the possible scenarios and intricacies of enforcing the summary judgment.2012 Total views17 Total
Jack Dorsey Calls Bitcoin a ‘Big Part’ of Twitter’s Future as a Global Currency
Jack Dorsey Calls Bitcoin a "Big Part" of Twitter"s Future as a Global Currency Twitter CEO Jack Dorsey says that bitcoin will be a big part of the company&rsquo
Internet Company The9 Reveals Hosting Partnership With Russian Bitcoin Miner Bitriver
Internet Company The9 Reveals Hosting Partnership With Russian Bitcoin Miner Bitriver During the first week of April, the publicly-listed gaming and internet com
Apecoin Integrates With Polygon, DAO Board Member Says Native APE Chain Was Never Discussed
Apecoin Integrates With Polygon, DAO Board Member Says Native APE Chain Was Never Discussed Following one of the largest non-fungible token (NFT) mints in history and after apecoin