Disrupting malicious uses of AI by state-affiliated threat actors
openai.com
openai.com
I wonder who came up with those. The pattern is similar to the UK's https://en.wikipedia.org/wiki/Rainbow_Code , which makes me suspect that the threat actor attribution comes from US intelligence. With whom OpenAI are almost certainly cooperating.
Edit: Forest Blizzard == GRU, apparently. https://research.splunk.com/stories/forest_blizzard/
Microsoft shifts to a new threat actor naming taxonomy → https://www.microsoft.com/en-us/security/blog/2023/04/18/mic...
[0] https://www.reuters.com/world/india/india-pivots-away-russia...
What makes you say that ? Can you point to some interesting discussions / reporting ?
1) The group themselves declares it (like Anonymous). Which means they need to explicitly leave their name somewhere.
2) The name is given by someone from the outside, such as the US.
I suspect 2 is quite common. I wouldn't expect most state level hackers leaving calling cards on systems. In fact, probably not most hackers at any level. It really seems like if state level actors were leaving calling cards that this would instead be misdirection rather than a tag. So I would not be surprised if they ended up getting US style naming schemes because it would be US (or other Westerners) identifying these people the same way you'd identify people by the style of actions and how they write. I know you can probably look at code from coworkers and know who wrote specific parts. Think like what you see in a movie with serial killers (or even real life). How do you know it is the same killer? Style.
I mean you could also get the name if you infiltrated the other country and then intimately studied their groups. The name of their group internally. But then you'd probably translate it. Still probably not a great idea to give that name out publicly though because then you could be hinting at how you obtained that information because different parts of the organization may refer to the same group by different names (specifically to do this. Military groups often run disinformation internally in secret channels).
Edit: guessmyname left a link to showing Microsoft names these.
https://www.microsoft.com/en-us/security/blog/2023/04/18/mic...
> Charcoal Typhoon used our services to research various companies and cybersecurity tools, debug code and generate scripts, and create content likely for use in phishing campaigns.
> Salmon Typhoon used our services to translate technical papers, retrieve publicly available information on multiple intelligence agencies and regional threat actors, assist with coding, and research common ways processes could be hidden on a system.
> Crimson Sandstorm used our services for scripting support related to app and web development, generating content likely for spear-phishing campaigns, and researching common ways malware could evade detection.
> Emerald Sleet used our services to identify experts and organizations focused on defense issues in the Asia-Pacific region, understand publicly available vulnerabilities, help with basic scripting tasks, and draft content that could be used in phishing campaigns.
> Forest Blizzard used our services primarily for open-source research into satellite communication protocols and radar imaging technology, as well as for support with scripting tasks.
Imagine a massive flood of low-quality images relevant to current events (e.g. war), which are obviously fabricated to anyone remotely aware of AI generation. But there are a lot of people who aren't aware of AI generation, or just not paying attention, who will take the photos at face value. (You'd probably be one of the latter. How many times did you "inspect" a photo in a news article to make sure it wasn't faked? How many of those photos slipped past inspection into your subconscious? Subliminal messaging has never been easier or more widespread.)
Also imagine a lot of vigilantes who are stupid enough to be vigilantes in this day and age, who ordinarily couldn't do the bare minimum amount of research to cause real harm. But now they can ask ChatGPT "how do I rob a bank?" and get advice which is still pretty bad, but better than what they'd come up with on their own (if they wouldn't just give up entirely), so it causes more damage.
A trained professional who wants a quality deepfake can already use photoshop and video editing tools, and a trained criminal already knows how to do research. But there aren't a lot of those people. Massive low-quality spam and low-level crimes are useful even for a state actor with huge resources, because they cause general instability in ways a few quality hits can't.
There's another issue that a powerful state actor can simply build and deploy their own language model. However, it probably won't be as good as OpenAI's (quality may have some effect) and it won't be wasting their resources.
Have you seen photorealistic Midjourney images? I can never distinguish many of them in a million years.
Confirmation bias and...love for the outgroup...is so strong, that it's rare people admit they didn't know it was fake and remove it. Frequently, someone else hops in, to explain it feels true and represents how they understand $OPPOSITION's viewpoint anyway.
Once multiple people get involved, semi-frequently, it turns into an indictment of the person who pointed out the fake. Why? Even if it is a fake, the real ignorance exposed is that of the person pointing out the fake, as it's clearly representative of $OPPOSITION anyway, so they're at best naive, and at worst supportive of, $OPPOSITION.
It does make it easier, and who knows about the future. But right now if you generate an image you have to really look and there's a good chance at least something's off.
Specific example: https://www.reddit.com/r/ChatGPT/comments/1apyrwv/which_vide.... They are video games so already not realistic, but no gym has people stand around like that and all of them have some nonsensical equipment.
It will be like the pro-state people having assistants to create memes they imagine for them, while the anti-state people are left with paper and crayons, until the AI paper and AI crayons refuse to draw anti-state memes and then we find anti-state activists trying to learn bee keeping so they can get wax to make crayons to draw anti-state memes.
If you thought the election interference of the past was bad, that's nothing compared to what we will see in the near future.
If anything the best thing about this post is not the actions they've taken, but simply that they've shown us a snapshot of what the future will look like for state-affiliated actors' actions. The research aspect I think is a good thing - giving people full access to more information for how things are made and architected will likely be a net positive. The phishing aspect though is terrifying - it's going to be crazy seeing what the next decade looks like for phishing. I do wonder how long it takes before there's some sort of "verified as a human" type function in communications to try and combat this.
This means the same information you get from ChatGPT is available from a Google search. Based on the listed queries ("programming help") ChatGPT does not create much value for national security threat actors here.
https://help.openai.com/en/articles/7730893-data-controls-fa...
https://www.washingtonpost.com/archive/politics/2004/02/27/r...
- "In January 1982, President Ronald Reagan approved a CIA plan to sabotage the economy of the Soviet Union through covert transfers of technology that contained hidden malfunctions, including software that later triggered a huge explosion in a Siberian natural gas pipeline, according to a new memoir by a Reagan White House official."
This is the actually concerning one imo. Pair that with Russia's '21 ASAT demo and it shows a militaristic stance towards space by a great (ish) power
With what GPUs?
The real concern in my mind is use cases aimed at swaying opinions in aggregate via large amounts of real seeming AI actors. Attempts to move the Overton window etc. for that sort of mass psychology patios LLMs are perfect
Meanwhile their actions suggest they're first and foremost interested in benefiting themselves and whoever's given them the most money, which certainly isn't their users.
e.g. does datafusion or polars support partial reads of parquet files in s3?
I wonder if they've rolled out some draconian restrictions.
Im surprised one can name names like that.
https://www.theguardian.com/world/2023/dec/01/the-gospel-how...
https://www.cnbc.com/2024/01/16/openai-quietly-removes-ban-o...
Let's say some state-level entity asks OpenAI for access to its best code generating models to help it build software for autonomous kill vehicles that use face recognition algorithms to assassinate human targets. Most people would classify the end product as "a thing that should be banned internationally".
Consider IBM's history - IBM supplied its machines and technology to just about any private or state entity willing to sign a contract - and in most cases the result was beneficial to every sector of the economy, and improved government efficiency as well. IBM survived the Great Depression in part with a large Social Security management contract from FDR, and had several large military contracts afterwards, including in Vietnam for a decade. But there was also the German arm of the business in the 1930s, which I'd hope IBM leadership regrets in hindsight.
As the LLM technology platform seems a bit difficult to monetize at present, it's likely that the sector will be looking at large government contracts to sustain its growth over the next decade (see AWS and $10 billion for the NSA's "WildandStormy" contract (yes really)). Thus it would be nice to hear industry leaders explicitly state that using AI systems to write code for autonomous kill vehicle operations or to mine phone records for automated generation of assassination lists is unacceptable.
Transparency is going to be an issue - secret contracts for AI services should not be allowed.
Yawn.
C'mon, tell me how you canned state-affiliated USA accounts and what they were up to.
Techno-optimists are delusional if they don't get spooked by things like this, which will happen if we as a species somehow can't get over authoritarian dictatorships within a few years to a few decades. Which we won't.
Me, I'm worried by the possibility of a "You Gotta Believe Me" attack[0]: even if done with the best of intentions (and everyone thinks they're on the good team), it risks a memetic monoculture: https://kitsunesoftware.wordpress.com/2019/12/30/memetic-mon...
[0] As fictionalised by Vernor Vinge in Rainbow's End
Charcoal Typhoon used our services to research various companies and cybersecurity tools, debug code and generate scripts, and create content likely for use in phishing campaigns.
Also known as totally legal things. When did a supermarket conducted research into who is using the knives they sold for murder and selectively blocking them from buying knives as well as other goods?Anyway, to do away with the analogy, OpenAI isn't obligated to let these groups continue using their services just because they aren't doing something that isn't illegal. The groups are "enemies of the West", and at the very least they don't want the bad publicity of some news org finding out they were complicit.
This whole thing about protected classes is just a workaround to mitigate the excesses of this attitude where you can dispense your own justice in the first place.
Imagine if Al Capone was a black trans woman. Are you suddenly not allowed to not sell her a book about how to run a mob just because she's a protected class (all other things being equal)?
Wouldn't it be simpler if one could just say that we're all equal and it's simply illegal to discriminate in the first place (presumption of innocence etc etc).
This is going to be more and more relevant as people's reputation can be destroyed with a tweet without any proof.