{"id":2889,"date":"2024-04-01T15:52:40","date_gmt":"2024-04-01T20:52:40","guid":{"rendered":"https:\/\/www.darkreading.com\/threat-intelligence\/cybercriminals-options-lms-buy-build-break"},"modified":"2024-04-01T15:52:40","modified_gmt":"2024-04-01T20:52:40","slug":"cybercriminals-weigh-options-for-using-llms-buy-build-or-break","status":"publish","type":"post","link":"https:\/\/ddi.mohflo.net\/index.php\/2024\/04\/01\/cybercriminals-weigh-options-for-using-llms-buy-build-or-break\/","title":{"rendered":"Cybercriminals Weigh Options for Using LLMs: Buy, Build, or Break?"},"content":{"rendered":"<div class=\"media_block\"><a href=\"https:\/\/i0.wp.com\/eu-images.contentstack.com\/v3\/assets\/blt6d90778a997de1cd\/blt74db3792e56fc91e\/6605db09a92a45403529f239\/poptika-electric-AI-shutterstock.jpg?ssl=1\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/04\/cybercriminals-weigh-options-for-using-llms-buy-build-or-break.jpg?w=640&#038;ssl=1\" class=\"media_thumbnail\"><\/a><\/div>\n<div><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/04\/cybercriminals-weigh-options-for-using-llms-buy-build-or-break.jpg?w=640&#038;ssl=1\" class=\"ff-og-image-inserted\"><\/div>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Searching for ways to use large language models (LLMs) to streamline attacks and dodge defenses, cyberattackers face three choices: play a cat-and-mouse game to evade the guardrails put in place by the makers of major AI models like ChatGPT; spend the time and effort to train their own AI model; or conscript an uncensored open source model or something from the Dark Web to do their bidding.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Last month, underground developers appeared to have taken the first approach, releasing an AI-powered malicious front-end service, Dark Gemini, that likely modified prompts sent to legitimate LLMs to break restrictions on writing malicious programs and geolocating people in photographs. While many security professionals were not impressed with the capabilities demonstrated by the service, the <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a href=\"https:\/\/www.linkedin.com\/posts\/gadievron_informationsecurity-cybercrime-riskmanagement-activity-7177971029774921728-FYgz\/\" target=\"_blank\" class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" rel=\"noopener\">chatbot did show<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> what could be accomplished with little effort.&nbsp;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">While Dark Gemini has not made much of a splash, the systematic approach of creating a front end to bypass the guardrails restricting legitimate LLMs shows that a minimalist approach can deliver significant AI capabilities, such as text synthesis and translation, to make current attacks, such as phishing, more effective.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Offensive AI: Subvert, Buy or Build?\">Offensive AI: Subvert, Buy or Build?<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Dark Gemini is the latest example of finding ways to trick &#8220;born good&#8221; AIs into doing the dirty work. In February, Microsoft and Open AI <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a href=\"https:\/\/www.darkreading.com\/threat-intelligence\/microsoft-openai-nation-states-are-weaponizing-ai-in-cyberattacks\" target=\"_blank\" class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" rel=\"noopener\">warned that nation-state threat actors<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> \u2014 including those from China, Iran, North Korea, and Russia \u2014 were using the firms&#8217; LLMs to augment the threat groups&#8217; operations. Earlier this month, researchers at AI security firm HiddenLayer noted that the guardrails set up to limit unsafe responses from Google&#8217;s Gemini could <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a href=\"https:\/\/www.darkreading.com\/cyber-risk\/google-gemini-vulnerable-to-content-manipulation-researchers-say\" target=\"_blank\" class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" rel=\"noopener\">easily be bypassed<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Yet using AI for more complex components of an attack \u2014 such as building sophisticated malware \u2014 will likely prove difficult enough with the hurdles created by current guardrails, says Dov Lerner, security research lead at threat intelligence firm Cybersixgill.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;To truly be effective, [any malware] needs to be evasive, it needs to dodge any sort of defenses that are there, and certainly, if it&#8217;s malware being deployed on an enterprise system, then [it] needs to be very sophisticated,&#8221; he says. &#8220;So I don&#8217;t think AI can write [malware] programs right now.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Enter &#8220;born malicious&#8221; options for sale on the Dark Web. Already, AI chatbots trained on content from the Dark Web have proliferated, <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a href=\"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/wormgpt-cybercrime-tool-heralds-an-era-of-ai-malware-v-ai-defenses\" target=\"_blank\" class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" rel=\"noopener\">including FraudGPT, WormGPT, and DarkBART<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">. Uncensored AI models based on Llama2 and the hybrid Wizard-Vicuna approaches are also available as pre-trained downloads from repositories.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Other approaches, however, will likely lead to more serious threats. Cybercriminals with access to <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a href=\"https:\/\/www.darkreading.com\/application-security\/hugging-face-ai-platform-100-malicious-code-execution-models\" target=\"_blank\" class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" rel=\"noopener\">unrestricted AI models through HuggingFace<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> and other AI-model repositories could create their own platforms with specific capabilities, says Dylan Davis, threat intelligence analyst at Recorded Future&#8217;s Insikt Group.&nbsp;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;The impact unrestricted models will have on the threat landscape&#8221; will be significant, he says. &#8220;These models are easily accessible &#8230;, easy to stand up, [and] they\u2019re constantly improving \u2014 much better than most [Dark Web] models \u2014 and getting more efficient.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;This is typical of the cybersecurity arms race that repeats itself over and over,&#8221; says Alex Cox, director of the threat intelligence team at LastPass. &#8220;With a disruptive technology like AI, you see quick adoption by both good and bad guys, with defensive mechanisms and process being put in place by the good guys.&#8221;<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"The AI Arms Race &amp; Defense Strategies\">The AI Arms Race &amp; Defense Strategies<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">As attackers continues to search for ways of using AI, defenders will be hard-pressed to maintain <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a href=\"https:\/\/www.darkreading.com\/cyber-risk\/forget-deepfakes-or-phishing-prompt-injection-is-genai-s-biggest-problem\" target=\"_blank\" class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" rel=\"noopener\">AI guardrails against attacks like prompt injection<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, says Recorded Future&#8217;s Davis. To create defenses that are hard to bypass, companies need to conduct in-depth adversarial testing, to create rules designed to filter out or censor both inputs and outputs \u2014 an expensive proposition, he says.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;Adversarial training is currently one of the more robust ways to [create] a resilient model, but there\u2019s a massive tradeoff here between safety and model ability,&#8221; Davis says. &#8220;The more adversarial training, the less &#8216;useful&#8217; the models become, so most model creators will shy on the side of usability, as any sane business would.&#8221;&nbsp;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Defending against underground developers creating their own models, or using pretrained open source models in ways that were not anticipated, is nearly impossible. In those cases, defenders have to treat such tools as part of the cybersecurity arms race and adapt as attackers gain new capabilities, LastPass&#8217; Cox says.&nbsp;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;Guardrails and generative AI safety should be viewed like any other input validation process, and the protections need to be evaluated, re-evaluated, and red-teamed on a regular basis as capabilities improve and vulnerabilities are discovered,&#8221; he says. &#8220;In that sense, it\u2019s just another technology that needs to be managed in the vulnerability assessment world.&#8221;<\/span><\/p>\n<p><a href=\"https:\/\/www.darkreading.com\/threat-intelligence\/cybercriminals-options-lms-buy-build-break\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Searching for ways to use large language models (LLMs) to<\/p>\n","protected":false},"author":12,"featured_media":2890,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1],"tags":[809],"class_list":["post-2889","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-dark-reading"],"featured_image_urls":{"full":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/04\/cybercriminals-weigh-options-for-using-llms-buy-build-or-break.jpg?fit=1600%2C900&ssl=1",1600,900,false],"thumbnail":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/04\/cybercriminals-weigh-options-for-using-llms-buy-build-or-break.jpg?resize=150%2C150&ssl=1",150,150,true],"medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/04\/cybercriminals-weigh-options-for-using-llms-buy-build-or-break.jpg?fit=300%2C169&ssl=1",300,169,true],"medium_large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/04\/cybercriminals-weigh-options-for-using-llms-buy-build-or-break.jpg?fit=640%2C360&ssl=1",640,360,true],"large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/04\/cybercriminals-weigh-options-for-using-llms-buy-build-or-break.jpg?fit=640%2C360&ssl=1",640,360,true],"1536x1536":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/04\/cybercriminals-weigh-options-for-using-llms-buy-build-or-break.jpg?fit=1536%2C864&ssl=1",1536,864,true],"2048x2048":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/04\/cybercriminals-weigh-options-for-using-llms-buy-build-or-break.jpg?fit=1600%2C900&ssl=1",1600,900,true],"chromenews-featured":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/04\/cybercriminals-weigh-options-for-using-llms-buy-build-or-break.jpg?fit=1024%2C576&ssl=1",1024,576,true],"chromenews-large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/04\/cybercriminals-weigh-options-for-using-llms-buy-build-or-break.jpg?resize=825%2C575&ssl=1",825,575,true],"chromenews-medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/04\/cybercriminals-weigh-options-for-using-llms-buy-build-or-break.jpg?resize=590%2C410&ssl=1",590,410,true]},"author_info":{"display_name":"Dark Reading","author_link":"https:\/\/ddi.mohflo.net\/index.php\/author\/darkreading\/"},"category_info":"<a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/uncategorized\/\" rel=\"category tag\">Uncategorized<\/a>","tag_info":"Uncategorized","comment_count":"0","jetpack_featured_media_url":"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/04\/cybercriminals-weigh-options-for-using-llms-buy-build-or-break.jpg?fit=1600%2C900&ssl=1","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/2889","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/comments?post=2889"}],"version-history":[{"count":0,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/2889\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media\/2890"}],"wp:attachment":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media?parent=2889"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/categories?post=2889"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/tags?post=2889"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}