Security News > 2023 > September > UK’s NCSC Warns Against Cybersecurity Attacks on AI
The National Cyber Security Centre provides details on prompt injection and data poisoning attacks so organizations using machine-learning models can mitigate the risks.
Large language models used in artificial intelligence, such as ChatGPT or Google Bard, are prone to different cybersecurity attacks, in particular prompt injection and data poisoning.
AIs are trained not to provide offensive or harmful content, unethical answers or confidential information; prompt injection attacks create an output that generates those unintended behaviors.
Prompt injection attacks work the same way as SQL injection attacks, which enable an attacker to manipulate text input to execute unintended queries on a database.
A less dangerous prompt injection attack consists of having the AI provide unethical content such as using bad or rude words, but it can also be used to bypass filters and create harmful content such as malware code.
Prompt injection attacks may also target the inner working of the AI and trigger vulnerabilities in its infrastructure itself.
News URL
https://www.techrepublic.com/article/uks-ncsc-warns-against-cybersecurity-attacks-on-ai/
Related news
- How life sciences companies use AI to fill the cybersecurity skills gap (source)
- The role of AI in cybersecurity operations (source)
- UK health services call-handling vendor faces $7.7M fine over 2022 ransomware attack (source)
- Unlock the Future of Cybersecurity: Exclusive, Next Era AI Insights and Cutting-Edge Training at SANS Network Security 2024 (source)
- Foiling bot attacks with AI-powered telemetry (source)
- Webinar: Learn to Boost Cybersecurity with AI-Powered Vulnerability Management (source)
- AI cybersecurity needs to be as multi-layered as the system it’s protecting (source)
- Benefits and best practices of leveraging AI for cybersecurity (source)
- Top priorities for federal cybersecurity: Infrastructure, zero trust, and AI-driven defense (source)
- UK arrests teen linked to Transport for London cyber attack (source)