LLM attacks take just 42 seconds on average, 20% of jailbreaks succeed
scworld.com
scworld.com
Quite the opposite: nothing we know about security is changing because of LLMs:
Everybody who is at least somewhat knowledable about security topics can tell you that adding some some AI chat(terbot) to anything security-related is a really bad idea. The only new thing about IT security that has changed is that such sound advice now becomes ignored because of the gold rush.
So nobody. And everyone will add chat bots. And the security will suffer, exactly as the article says.
But there are much more informed ML people out there than me, so I assume this and similar techniques have already been thought of.
But then, you have two independent mechanisms that can get out of sync, a classic source of issues in infosec - except both are also more or less inscrutable and fail in unexpected ways.
The LLM is just generating orders of magnitude more user state as a result of a prompt. The actions the LLM is permitted to take must still be gated on the authorizations allowed for that user. This means that data unavailable to the user must not be in the training set of the LLM acting as an interface layer.
The "we have to learn new lessons" only applies when you lump all data together and hope the LLM doesn't spit up someone else's data from a probabilistic elbow jog. Hope is not a strategy.