NIST Alerts AI Developers: Beware of Poisoning Methods and Cyber Threats

January 16, 2024
1 min read

In a new guideline paper, the National Institute of Standards and Technology (NIST) has highlighted the potential cyber threats that AI developers may face during the development and deployment of their models. The paper focuses on “poisoning” methods, where training data is tainted to manipulate the learning model, as well as “evasion” attempts to confuse AI already in use and prompts used by cyber threats to “jailbreak” the models. The paper also highlights the vulnerability of AI models during the learning phase, as they rely on large volumes of public data, which may contain misinformation. The paper suggests that while developers cannot completely secure their models, they should carefully consider potential attack sources and approaches to make trade-offs between capability and security.

The paper also discusses the risks of altering the source code of AI models, as many developers use open source components or third-party libraries. It highlights the difficulty of curating the large volume of information required for training AI models and the risk of unintentional self-poisoning as models generate synthetic content. The paper acknowledges that there are no foolproof methods for curbing these threats and recommends mapping out anticipated attack sources and approaches.

Latest from Blog

Bridging the cyber talent gap: tips for CISOs

TLDR: – Global cyber threats have increased twofold in recent years, leading to a talent gap of nearly 4 million cyber professionals worldwide. – Existing cyber staff are under strain, with vacancies

North Korean hackers pivot to ransomware attacks

TLDR: North Korean hackers from APT45 have shifted from cyber espionage to ransomware attacks APT45 has targeted critical infrastructure and is linked to ransomware families SHATTEREDGLASS and Maui A North Korea-linked threat

Cyber insurance evolves to cover all your online needs

TLDR: Cyber insurance coverage is evolving to help raise security baselines across businesses. Only one-quarter of companies have a standalone cyber insurance policy. In today’s evolving cybersecurity landscape, cyber insurance coverage is