CDSA 2024年10月10日
CDSA at IBC: ConvergentDS Examines AI Threats
index_new5.html
../../../zaker_core/zaker_tpl_static/wap/tpl_guoji1.html

 

AI在多个领域的应用快速发展,但也带来诸多安全问题。如AI眼镜可能导致内容泄露、成为黑客目标,AI还被用于各种欺诈行为等。同时,也提出了一些应对方案,如输入验证、访问控制等。

🎈AI应用广泛,如苹果与OpenAI合作、Bumble应用约会AI等,但新AI工具和应用带来大量安全问题,如AI眼镜若未妥善保护,易导致内容泄露并成为黑客目标,数据收集问题也令人担忧。

💥AI带来的安全威胁多样,包括提示注入、不安全的输出处理、数据泄露、DDoS攻击、不安全的插件、权限问题等,黑客可利用AI多种手段入侵电脑、操纵模型行为。

🌟针对AI入侵,有一些解决方案,如输入验证和净化、基于角色的访问控制、安全提示设计、正则表达式检查,以及至关重要的持续监控,定期审计和评估也有帮助。

From Apple finalizing a deal with OpenAI for ChatGPT iPhone integration, to the dating app Bumble integrating a dating AI “concierge” for its users, to AI-powered, wearable pins and glasses that serve as smartphone alternatives, the applications for AI are coming at everyone fast these days.

And with all these new AI tools and apps comes a boatload of security headaches.

“What you are dealing with, especially looking around at content security, what’s super scary about [AI wearables], Is you’re basically allowing somebody to walk into your organization and record everything,” Justin Whitehead, chief chaos officer for cybersecurity firm ConvergentDS said, speaking at the recent CDSA Summit at IBC. Even if your good about using watermarks on your content, it’s all for naught if someone is right there recording as the content is being made.

Whitehead’s and ConvergentDS’s CTO Ben Stanbury’s presentation — “Using AI Tools to Make us Safer” — offered attendees a better understanding of what security risks to look for when using AI tools in the M&E production supply chain. And boy are they varied.

Not only are those AI glasses a massive content leak waiting to happen, if the glasses aren’t properly secured, they’re a ripe target for hackers, with unauthorized individuals accessing recorded footage, voice commands, any number of points of sensitive information. The unauthorized data collection concerns alone are enough to keep a cybersecurity head up at night.

“The devices are being put out there so quickly, that some of the things that you guys are going to have to compete against are going to be [happening] on a daily basis,” Whitehead said.

Just look at the news for real-life AI headaches for the media and entertainment industry: A North Carolina musician was charged with using AI to create hundreds of thousands of songs that he streamed billions of times to rake in roughly $10 million in royalty payments. Singapore is looking at banning deepfakes and other digitally manipulated content of political candidates during elections because the technology has gotten so out of hand.

Generative AI is being used to create content and impersonate individuals in wire fraud schemes. And, worldwide, content has simply become too difficult to determine which is
truth and which is satire.

The threats around AI are familiar to cybersecurity experts: prompt injections, insecure output handling, data leakage, DDoS, insecure plugins, permission issues. Hackers can use AI to backdoor into computers, using the right prompts and some Chinese characters. Attackers are modifying training data to manipulate AI model behavior. You can tell AI you’re someone you’re not and convince it to allow access to all sorts of things.

You can even confuse some AI and trick it into coughing up privileged data, just by repeating the same word (“cool”) at it over, and over, and over again.

“Some of the use of AI and web sites [are] taking backend data, collecting what’s been on my computer, and it’s [determining my gender], it’s making it more feminine, it’s making it more masculine, it’s writing it more at a CTO level, it’s writing it more at a CEO level,” Whitehead said.

Fortunately, there’s solutions that can be thrown up against this horde of AI intrusions, including input validation and sanitization, role-based access control, secure prompt design, regular expression checks, and crucially, constant monitoring. And regular audits and assessments don’t hurt either.

To watch the full presentation, click here. To view the presentation slide deck, click here.

All presentations from the Sept. 13 CDSA at IBC event, including from AMD’s John Canning, Ben Schofield, technical director of CDSA, Hollie Choi, managing director of the Entertainment ID Registry Association (EIDR), and more, can be found here.

The Content Delivery & Security Association (CDSA) will host its next event, the CDSA Summit Los Angeles, on Dec. 9, with a special event for CDSA members the following day.

The theme of the Dec. 9 summit will be “Where AI and Content Protection Converge.” For more information about the CDSA Summit Los Angeles click here.

For sponsorship and speaker inquiries, email secretariat@CDSAonline.org

Fish AI Reader

Fish AI Reader

AI辅助创作,多种专业模板,深度分析,高质量内容生成。从观点提取到深度思考,FishAI为您提供全方位的创作支持。新版本引入自定义参数,让您的创作更加个性化和精准。

FishAI

FishAI

鱼阅,AI 时代的下一个智能信息助手,助你摆脱信息焦虑

联系邮箱 441953276@qq.com

相关标签

AI应用 安全问题 解决方案 内容泄露 黑客攻击
相关文章