OpenAI Cybersecurity Grant Program
openai.com
openai.com
Semi underground stuff like Phrack, 2600 and various punky groups who surprisingly did good security research and open to participation..
Today's cutting edge security research feels very silod in the products.
OWASP Top 10 for Large Language Model Applications
https://owasp.org/www-project-top-10-for-large-language-mode...
The draft of the Top 10
https://owasp.org/www-project-top-10-for-large-language-mode...
https://simonwillison.net/2023/May/2/prompt-injection-explai...
I am excited for AI-based threat intelligence products, though.
Threat intel has purported to use AI for ages and I remain unconvinced of its effectiveness. Program analysis to support TI could be exciting however.
Even academics are asking the LLM itself to describe what it's doing like idiots. I know that academia's intellect is slipping due to allowing too many people in, but this type of stupidity is just mind boggling.
But absolutely agreed, just listened to Gary Marcus’s podcast episode on how LLMs are already capable of making dad jokes, but they can’t do neither “deep” humor generation nor “deep” humor explanation very well, in part because they lack all of the cultural and experiential (“touchy-feely”) context of the humans, and an even bigger part since they are optimized for generation, not explanation, while humans are almost the opposite.
IMO encoder models are far more powerful and useful for devs than any of the decoder models.
Have examples of existing product or project in this space that are interesting to you?
Additionally, even OpenAI’s own advertisement “paper” acknowledges they couldn’t make it work for pentesting well (hence probably why they created this bounty program, among other reasons).
“Gorilla: Large Language Model Connected with Massive APIs” https://arxiv.org/abs/2305.15334
Cybersecurity is certainly one of the near term (now?) AI related risks.
This should help encourage some defensive progress.
That said there are things they could do to prevent this. They won't do them, it'd be costly research... But they could.
That said, more traditional approaches (non-ML) are probably more effective still.
It could give some safety if skynet becomes a thing, of course super AI will learn to disable it in a week, but still maybe there's a path there to mitigation of future threats?
I'd be very surprised if secretive agencies within the USA, China, Israel, Russia and others weren't going full-bore on the offensive side (which OpenAI says this particular grant program is not involved in, at least, but I wonder what the black-budget NSA-TAO side of things looks like at present).
1. Create something that monitors an app's network connections
2. Use the data to auto-generate integration tests for every endpoint including edge cases, error states, etc
3. Have user validate and accept the integration tests
(end there for self-serve tier, and for the enterprise tier...)
4. Rewrite app into another language, framework, or simply refactor code to be cleaner, more consistent, convert callbacks to promises or async/await, etc.
... key step being #3, need a really good test suite to validate the new code works the same as the old.
Does "increments of $10k" mean that a single grant can be greater than $10k? Or are grants limited to that amount?