Agregátor RSS
Microsoft unveils AI security tools it says outperform competing platforms
Microsoft is introducing new AI tools designed to help customers continuously streamline and automate the process of identifying and reducing their exposure to security risks.
The new tools come less than a week after OpenAI lost control of two of its security models when they infiltrated the servers of startup Hugging Face. The hack, Hugging Face added, involved “a swarm of tens of thousands of automated actions” that stole internal Hugging Face credentials. The OpenAI models achieved this feat by exploiting a zero-day flaw in Hugging Face’s data-processing pipeline to run malicious code that escalated the models’ access to the company’s high-value cloud and server clusters.
Microsoft’s announcements on Monday made no reference to the event, which OpenAI said was “unprecedented.” The company also didn’t say what would prevent the new tools from similarly going rogue.
Open Secure AI Alliance
ČSOB mění podmínky. Přidá okamžité SEPA platby, upraví Kate Coiny a služby pro děti
New Dysphoria DDoS botnet spreads to 200k devices worldwide
New Certighost PoC exploit lets attackers hijack Windows domains
Weak AI Regulation Could Be Worse Than None at All
A Cornell University study uses game theory to model how poorly designed AI regulation could backfire.
Governments around the world are racing to regulate AI before it becomes too deeply embedded in society. But new research suggests poorly designed rules could make AI systems less safe than having no regulation at all.
Regulatory disagreements in the US are leading to a patchwork of approaches as states take matters into their own hands. A key question is who should be responsible for the safety of AI products—the big tech companies building the underlying models or the firms that adapt them for a particular task, such as a customer service chatbot or an AI tutor.
Working this out is trickier than it looks. While it might seem logical to put the bulk of the burden on downstream companies directly serving these tools to customers, a new study in Proceedings of the National Academy of Sciences finds that could be worse than having no rules at all.
“There’s a free-riding behavior that occurs,” Benjamin Laufer from Cornell University, who led the research, said in a press release. “The regulation acts as a tool for the general provider to offload the safety burden onto the downstream specialist.”
The researchers’ analysis relied on a model based on game theory—a mathematical approach to studying decision making. It treated AI development as a two-step game, in which a “generalist” developer first invests in building a broadly capable AI model before a “specialist” adapts it for a specific domain and takes it to market.
In the game, a regulator sets a minimum safety standard for both players, and the models see this in advance. They then invest in both the performance and safety of their product, and the revenue is split between them. Investments in both get progressively higher, while the extra revenue each improvement brings in stays flat.
The problem, the researchers found, is that the generalist moves first and knows exactly what the specialist will be legally required to do afterwards. This creates problems when the generalist is set a low bar for safety, or none at all, and safety standards for the downstream specialist are also fairly weak.
In the absence of any rules, both firms invest in safety, because the model assumes a safer product earns more revenue. But if the specialist is forced to invest a certain amount into safety to meet regularity requirements, the generalist can cut its own spending and let the downstream firm close the gap.
That’s because the generalist’s revenue depends on the final safety level of the shipped product, not on its own contribution, so it can get a revenue boost from improved safety without paying for it from its own pocket. The specialist, for its part, has no reason to do more than the rule demands, so total safety settles at the legal minimum, which is below what would have occurred had there been no regulation at all.
On a more positive note, the researchers found that if safety levels on both the generalist and the specialist are set high enough, regulation can actually improve safety while leaving both companies more profitable than they were in an unregulated market.
“Appropriately designed AI regulation can make it possible for different firms involved in the AI development pipeline to collectively arrive at good outcomes for consumers, knowing that the regulation is designed to help each firm operate in a way that the others can more reasonably predict,” co-author Jon Kleinberg from Cornell University said in the press release.
However, the researchers’ model relies on the market setting a real price on safety. As the gap widens between what customers will pay for performance and what they’ll pay for safety, the range of circumstances in which weak rules backfire gets narrower.
The authors also note that the model’s two-player setup is a simplification of real AI supply chains where multiple competing specialists and base-model providers operate across different jurisdictions with different rules.
“People think of AI as a single object, but actually AI involves a very complicated set of stakeholders and actors that each have their own contributions to the technology,” said Laufer. “To regulate in a thoughtful way, we need to consider the whole supply chain, not just a single provider or entity.”
Still, the results suggest that taking an overly simplistic and light-handed approach to AI regulation may end up achieving the opposite of what law makers intend.
The post Weak AI Regulation Could Be Worse Than None at All appeared first on SingularityHub.
Hugging Face CEO wants transparency after OpenAI’s AI incident
Hugging Face CEO Clem Delangue wants to see radical transparency from OpenAI after the company acknowledged that one of its AI agents managed to hack into the AI platform’s systems during a test.
In a post on X, Delangue wrote that, among other things, he wants OpenAI to publish logs and traces from the autonomous AI agent so researchers can analyze what happened. He also called for better defensive tools and urged OpenAI to allocate $100 million worth of computing capacity to help the Hugging Face community develop stronger cybersecurity solutions.
“The first cyberattack by an autonomous AI agent is an unprecedented event. It deserves an unprecedented response,” Delangue wrote.
Microsoft's solution to AI security: more AI and more acronyms
Revolut nabídne soukromé fondy už od 1 eura. Výběr peněz ale může být omezený nebo odložený
NVIDIA Forms 37-Member Open Secure AI Alliance and Open-Sources NOOA Framework
Nový život pro šuplíkové telefony. Webová aplikace ScreenWall je promění v meteostanici či fotorámeček
Apple sued over fake App Store crypto wallet app stealing $1.8M in Bitcoin
Dysphoria IoT Botnet Adds Blockchain C2 and Victim Relays After JackSkid Disruption
Čím nahradit Total Commander? Těchto 16 správců souborů umí skoro totéž a většinou jsou zdarma
Installed Is Not Remediated: How to Verify Linux Security Patches in Production
Tech giants link hands to praise open AI models after OpenAI - Hugging Face attack
Krabix.cz, online 3D konfigurátor krabiček pro 3D tisk
Deset skrytých nastavení fotoaparátu iPhonu, díky kterým pořídíte výrazně lepší fotografie i videa
The best thing about Apple’s smart glasses: what Cupertino rejects
Despite the temptation to enter what might become a $40 billion market, Apple has reportedly decided to delay the introduction of its smart glasses until 2027. The company apparently wants to figure out a better balance between privacy and convenience.
If it gets that right, Apple might be able to bring to market glasses people can wear in public without making everyone around them wonder whether they, their children, their private conversations or even corporate data are being quietly recorded or filmed.
It’s a sensible move. During the first internet gold rush, many argued that trading privacy for convenience would be more than justified by the benefits. Years later, that bargain looks a great deal less attractive than it did.
We’ve seen this storyAfter all, since then we’ve seen the likes of Cambridge Analytica and the evolution of digital state surveillance (and state-adjacent surveillance “businesses” such as NSO). We’ve also seen the dubious rise of data brokers, creepy “personalized” ads that seem to follow private conversations around, and all the other parasites that breed in the murk when privacy is diluted.
None of these things is good. More people than ever now seem to understand that when privacy is removed, bad things happen — no matter what herds of fully paid-up lobbyists try to make people believe. Privacy erosion seems to be a great deal for ultra-wealthy corporations seeking to turn our lives into their profit. It is not such a great deal for the rest of us.
The next privacy frontier: Your faceThis growing awareness matters as we prep for the next big thing in disruptive technology: AI-equipped wearable devices capable of contextual understanding and analysis of surroundings. These smart, sensor-packed devices will pick up so much information about us, from health biometrics to direction, even insight into what we look at, how long, and what that gazing does to our heart rate. (Think of how useful the latter data point might become for divorce lawyers and blackmail.)
In the next wave of wearables, the data gathered about you will comprise an even more accurate depiction of who you are than what your smartphone already generates. These systems don’t just pick up the raw data about you; because they are AI-equipped, they also gather information about what you do and why you’re doing it. That might be useful some of the time, but is the convenience worth turning your whole life into a data point that can be interrogated, hacked, stolen, or abused? I’m not certain it is.
Apple’s opportunityFortunately, I’m not the only one. Apple seems to be rethinking some of the scariest features built into its future (2027) Meta-competing glasses, possibly with the introduction of software fixes to mitigate some of the more egregious ways these devices might be used to disrupt privacy.
This is good business, of course. Not only has Apple fought hardest to protect user privacy, but it also knows that Meta — its main competitor in the smart glasses space — has what could easily be seen as a poor record for privacy protection. With Apple about to enter the fray with its first set of AI wearables since Vision Pro, it must find ways to distinguish its business from Meta’s.
Privacy is one major way to do so – and Apple might be motivated in part by Meta’s attempts to use Europe’s Digital Markets Act to undercut more customer privacy than Apple thinks it should without informed customer consent. If Meta wants that kind of info from an iPhone or Apple Watch, it will make the same play to get data from any other wearables Apple might create.
What will Apple do?Apple’s plan boils down to ensuring its devices don’t collect data they shouldn’t. Bloomberg’s Mark Gurman points to the surveillance threat of existing products: “Consumers remain uneasy around people wearing camera-equipped glasses, unsure whether they’re being recorded during conversations at work, restaurants or other public places,” he concedes.
I agree Apple will not want to introduce products that undermine its reputation for privacy, though I reject his opinion that fears about privacy and smart glasses are “probably unfounded.” History already shows these things only seem harmless until they’re not.
Gurman tells us Apple will put a light in the glasses so we can tell when a wearer is filming us, and a feature that disables filming if the light is broken or faulty. The company could also launch glasses with no camera at all, no third-party checking of footage, and on-device (rather than cloud-based) data analysis. He also posits that Apple could include a camera but “hard-code” limits on how it can be used, meaning it might pick up ambient data to feed contextual AI analysis, but not capture video or images. Others have considered a privacy beacon to prevent other devices filming the wearer.
We will likely learn how Apple plans to make smart glasses dumb enough to wear without becoming a privacy pariah at WWDC 2027. Gurman says the products are unlikely to ship until that fall.
You can follow me on social media! Join me on BlueSky, LinkedIn, Mastodon and subscribe to my daily, human-curated Apple-related news round-up, The Core.
Coca-Cola confirms data theft in Fairlife ransomware attack
- « první
- ‹ předchozí
- …
- 3
- 4
- 5
- 6
- 7
- 8
- 9
- 10
- 11
- …
- následující ›
- poslední »



