@cigitalgem@sigmoid.social
@cigitalgem@sigmoid.social avatar

cigitalgem

@cigitalgem@sigmoid.social

software security #swsec machine learning security #mlsec Tech | Life | Music

This profile is from a federated server and may be incomplete. Browse more on the original instance.

cigitalgem, to ML
@cigitalgem@sigmoid.social avatar

The definition of "out over your skis"
https://www.theregister.com/2024/04/03/stability_ai_bills/

cigitalgem, to random
@cigitalgem@sigmoid.social avatar

NEW BIML Bibliography entry

https://arxiv.org/pdf/2303.09859.pdf

Trained on 100 million words and still in shape:
BERT meets British National Corpus

David Samuel et al

Efficient language learning with better data. Data versus computer. This dataset is 140,000 times smaller than GPT4's dataset.

https://berryvilleiml.com/references/

cigitalgem, to random
@cigitalgem@sigmoid.social avatar

NEW BIML Bibliography entry

https://dl.acm.org/doi/pdf/10.1145/3446776

Understanding Deep Learning
(Still) Requires Rethinking
Generalization

Chityuan Zhang, et al

Cool set of basic experiments probing generalization. Still no real insight.

https://berryvilleiml.com/references/

cigitalgem, to random
@cigitalgem@sigmoid.social avatar

NEW BIML Bibliography entry

https://arxiv.org/pdf/2401.08565.pdf

Tuning Language Models by Proxy

Alisa Liu et al

Pulling fine-tuning out of the black box to make it cheaper. Very much inside baseball (badly described and motivated). Clearly no cognitive science background. Technically very interesting.

https://berryvilleiml.com/references/

cigitalgem, to random
@cigitalgem@sigmoid.social avatar

NEW BIML Bibliography entry

https://arxiv.org/pdf/1706.03741.pdf

Deep Reinforcement Learning
from Human Preferences

Paul Christiano et al.

Reinforcement Learning with human defined partial goals. Step 2 of LLM creation. Economic tradeoff. Humans cheaper than machine. Alignment.

https://berryvilleiml.com/references/

cigitalgem, to random
@cigitalgem@sigmoid.social avatar

NEW BIML Bibliography entry

https://arxiv.org/pdf/2201.11903.pdf

Chain-of-Thought Prompting Elicits Reasoning in Large Language Models

Google: Jason Wei et al.

Credulous use of anthropomorphic language to describe association chains. Very few actual trials = anecdotal work.

https://berryvilleiml.com/references/

cigitalgem, (edited ) to random
@cigitalgem@sigmoid.social avatar

NEW BIML Bibliography entry

https://arxiv.org/pdf/2206.07682.pdf

Emergent Abilities of Large Language Models

Google: Jason Wei et al.

Non-standard definition of emergence (a proxy for surprize) makes this paper very misleading from a cognitive perspective. The benchmarks are an anthropomorphic mess.

https://berryvilleiml.com/references/

cigitalgem, (edited ) to random
@cigitalgem@sigmoid.social avatar

REVISED BIML Bibliography entry

https://arxiv.org/pdf/2001.08361.pdf

Scaling Laws for Neural Language Models

OpenAI: Kaplan et al

Easy, straightforward paper, seminal in the scaling literature. We revisited this one after four years. The only issue missing is any notion of data quality (vs data set size). Cardinality of compute and data is a good start.

https://berryvilleiml.com/references/

mattblaze, to random
@mattblaze@federate.social avatar

The XZ backdoor seems to have become a Rorschach test that shows whatever you already believed about the security of open source software against sabotage.

It clearly proves the inherent superiority of the open source model. Or the inherent vulnerability. One of those, definitely.

cigitalgem,
@cigitalgem@sigmoid.social avatar
cigitalgem, to random
@cigitalgem@sigmoid.social avatar

NEW BIML Bibliography entry

https://arxiv.org/pdf/2401.05300.pdf

I am a Strange Dataset: Metalinguistic Tests for Language Models

Tristan Thrush, et al

This is a toy paper. Why not focus on EASY and ERRORS instead of trying too hard to be clever? This paper ends up being just silly.

https://berryvilleiml.com/references/

cigitalgem, to random
@cigitalgem@sigmoid.social avatar

NEW BIML Bibliography entry

https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.100-2e2023.pdf

NIST: Adversarial Machine Learning

Apolstol Vassilev, et al

Laundry list of attacks without a very useful taxonomy. Spotty terminology. Suggests that pen testing is a good paradigm for solution. We found this one so problematic that we wrote it up on the blog. (https://berryvilleiml.com/2024/01/23/another-round-of-adversarial-machine-learning-from-nist/)

https://berryvilleiml.com/references/

mattblaze, to random
@mattblaze@federate.social avatar

Watched the Steve Martin doc on AppleTV. I hadn't noticed before (this is my observation, not the film's) how much Andy Kaufman honed characters that seem at least inspired by Martin's early work. Both did "bombing comedian" characters; Martin's was a clueless blowhard, while Kaufman's was a clueless innocent.

Anyway, fascinating career (and life) arc.

cigitalgem,
@cigitalgem@sigmoid.social avatar

@mattblaze I have heard good things. Recommended?

cigitalgem, to infosec
@cigitalgem@sigmoid.social avatar

I am giving two breakfast seminars back to back mid-April. If you are in Sweden, Norway or Finland, please consider coming. Pass it on to those who may be interested.

STOCKHOLM 17.4 https://www.lyyti.fi/reg/CDR-SV-17-04-2024

OSLO 18.4 https://www.lyyti.fi/reg/CDR-NO-18-04-2024

cigitalgem, to random
@cigitalgem@sigmoid.social avatar

You might think this is ironic. Or you might just think this is standard issue boring.
https://infosec.exchange/@BleepingComputer/112197603115281540

cigitalgem, to llm
@cigitalgem@sigmoid.social avatar

I am giving a talk @indianauniv in Bloomington THIS FRIDAY. I will cover security risks (that is ) identified by BIML. Open to the public.

https://spice.luddy.indiana.edu/garymcgrawtalk/

picture

cigitalgem, to random
@cigitalgem@sigmoid.social avatar

New @techtargetnews podcast features BIML LLM Risk Analysis work. This eposide is suitable for newbies to AI/ML.

https://targetingai.podbean.com/e/security-bias-risks-are-inherent-in-genai-black-box-models/

cigitalgem, to ML
@cigitalgem@sigmoid.social avatar

New podcast from TechTarget discusses BIML's LLM Risk Analysis in great detail. Have a listen.

https://berryvilleiml.com/2024/04/01/tech-target-podcast-biml-discusses-23-black-box-llm-foundation-model-risks/

cigitalgem, to random
@cigitalgem@sigmoid.social avatar

In case you missed it, Ross Anderson died unexpectedly before easter. He will be missed.

https://sigmoid.social/@cigitalgem/112179834313589598

spaf, to random
@spaf@mstdn.social avatar

You can't really know if any time is the last meeting, last kiss, last embrace ....

Unless you're the one pulling the trigger.

cigitalgem,
@cigitalgem@sigmoid.social avatar

@spaf you are so terrible!

cigitalgem,
@cigitalgem@sigmoid.social avatar

@spaf I knew that would be a favorite...

cigitalgem, to random
@cigitalgem@sigmoid.social avatar

Ross Anderson's first Silver Bullet episode (number 13 from 2007) was the most popular episode I ever recorded (out of 153 monthly episodes in a row). Ross recorded a second (number 70 in 2012). Here they are, moved to archive in 2018.

https://apothecaryshed.files.wordpress.com/2018/10/silverbullet-070-ross-anderson-2.mp3

https://apothecaryshed.files.wordpress.com/2018/10/silverbullet-013-ross-anderson.mp3

cigitalgem,
@cigitalgem@sigmoid.social avatar

Now I am saddened that I will no longer have conversations like those with Ross. We always had so much fun talking shop.

karlauerbach, to random
@karlauerbach@sfba.social avatar

@SteveBellovin Today you posted a note about how someone appears to have injected a Trojan into the source of XV. And there was another post about the increase in complex tool chains and dependencies that are larding-up the software many of us use.

That made me wonder about whether national security bodies - intelligence, military, or other - or social movements, e.g. ISI) might be injecting similar things into source trees.

It would be relatively easy to hide such things, particularly via the tool chains or Makefiles - like who is going to notice a sed script in a autoconfig part of a build chain?

Like good spies, such things could be planted years in advance and only triggered, if ever, when desired.

This is not an open source issue, it is a ubiquitous issue. And in light of Ken Thompson's "Reflections on Trust" some of these could be quite invisible in some kinds of source code.

I am very nervous about the vulnerability and brittleness of our new world of tech as a utility.

cigitalgem,
@cigitalgem@sigmoid.social avatar

@karlauerbach @SteveBellovin do you remember when the OpenBSD codebase was popped? Pretty sure you're on target.

swelljoe, to linux
@swelljoe@mas.to avatar

Does everyone understand how much luck was involved in this exploit in being discovered so quickly? And, what it tells us about the attacker?

This was a subtle and sophisticated attack implemented over years. The attacker was made a co-maintainer two years ago, and they made numerous innocuous-looking and seemingly unrelated changes over that time, sometimes through a second account, that eventually added up to a backdoor. Along with many innocent commits, too.

cigitalgem,
@cigitalgem@sigmoid.social avatar

@noplasticshower @swelljoe yeah, stop being mean to my sock puppet...it has thin skin for something that grew up on usenet

mattblaze, to random
@mattblaze@federate.social avatar

If you've not heard the news, Ross Anderson, professor at Cambridge and well known privacy scholar and security engineer, passed away unexpectedly at his home. A huge loss to his family, his friends, students, and colleagues, and to the community.

cigitalgem,
@cigitalgem@sigmoid.social avatar

@mattblaze same

  • All
  • Subscribed
  • Moderated
  • Favorites
  • megavids
  • InstantRegret
  • magazineikmin
  • modclub
  • Durango
  • Youngstown
  • rosin
  • khanakhh
  • slotface
  • ngwrru68w68
  • mdbf
  • thenastyranch
  • kavyap
  • DreamBathrooms
  • JUstTest
  • tester
  • everett
  • normalnudes
  • GTA5RPClips
  • osvaldo12
  • ethstaker
  • cisconetworking
  • tacticalgear
  • provamag3
  • Leos
  • cubers
  • anitta
  • lostlight
  • All magazines