{"id":3717,"date":"2024-05-23T09:00:00","date_gmt":"2024-05-23T14:00:00","guid":{"rendered":"https:\/\/www.darkreading.com\/cybersecurity-operations\/new-mindset-needed-for-large-language-models"},"modified":"2024-05-23T09:00:00","modified_gmt":"2024-05-23T14:00:00","slug":"new-mindset-needed-for-large-language-models","status":"publish","type":"post","link":"https:\/\/ddi.mohflo.net\/index.php\/2024\/05\/23\/new-mindset-needed-for-large-language-models\/","title":{"rendered":"New Mindset Needed for Large Language Models"},"content":{"rendered":"<div class=\"media_block\"><a href=\"https:\/\/i0.wp.com\/eu-images.contentstack.com\/v3\/assets\/blt6d90778a997de1cd\/blt4c40e86e69bd4300\/6627bbf80558d7673b19a5a6\/LLM_Bakhtiar_Zein_Alamy.jpg?ssl=1\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/new-mindset-needed-for-large-language-models.jpg?w=640&#038;ssl=1\" class=\"media_thumbnail\"><\/a><\/div>\n<div><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/new-mindset-needed-for-large-language-models.jpg?w=640&#038;ssl=1\" class=\"ff-og-image-inserted\"><\/div>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><span class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_bold\">COMMENTARY<\/span><\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">As a seasoned security architect, I&#8217;ve started to see the <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/vulnerabilities-threats\/bad-actors-will-use-large-language-models-defenders-can-too\" rel=\"noopener\">adoption of large language models<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&nbsp;(LLMs) across industries. Working with a diverse range of clients, from startups to Fortune 500 companies, I&#8217;ve witnessed firsthand the excitement and challenges that come with this transformative technology. One trend that&#8217;s been keeping me up at night is the potential for LLMs to be exploited in increasingly sophisticated ways.&nbsp;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">A recent incident with one of my clients really drove this home. The company, a large e-commerce platform, had deployed a <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cybersecurity-operations\/threat-modeling-in-the-age-of-openai-s-chatbot\" rel=\"noopener\">chatbot<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> powered by the open source platform called ChatterBot to handle customer inquiries. The chatbot was a hit, providing quick, personalized responses that improved customer satisfaction. However, things took a dark turn when a malicious actor figured out how to prompt the chatbot to reveal sensitive customer information.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The attacker started by engaging the chatbot in a seemingly innocuous conversation, building up a rapport. Then, they slowly steered the conversation toward more sensitive topics, using carefully crafted prompts to elicit information. The chatbot, lacking robust context understanding and not being trained to identify manipulative tactics, began divulging customer email addresses, phone numbers, and even partial credit card numbers.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Fortunately, the company&#8217;s security monitoring detected this anomalous chatbot behavior. Its AI-based threat detection system, which learns normal interaction patterns, alerted it to the unusual volume and content of the chatbot&#8217;s responses. The security team was quickly able to shut down the compromised chatbot before any major damage was done.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">But this close call was a stark reminder of the security risks that come with LLMs. These models are incredibly powerful, but they&#8217;re also inherently vulnerable to manipulation. Attackers are finding creative ways to <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/vulnerabilities-threats\/llms-open-manipulation-using-doctored-images-audio\" rel=\"noopener\">exploit LLMs<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, from extracting sensitive data to generating malicious content.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Best Practices for Security LLMs&nbsp;\">Best Practices for Security LLMs&nbsp;<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">So, what can be done to mitigate these risks? In my work with clients, I&#8217;ve been developing and implementing best practices for securing LLMs. Here are a few key lessons I&#8217;ve learned:<\/span><\/p>\n<h3 class=\"ContentText ContentText_variant_h3 ContentText_align_left\" data-testid=\"content-text\" id=\"1. Monitor, monitor, monitor.\">1. Monitor, monitor, monitor.<\/h3>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Comprehensive, real-time monitoring is essential for detecting LLM abuse. Traditional security monitoring often fails to catch the subtle, conversational nature of LLM attacks. That&#8217;s why I recommend specialized AI-based monitoring that understands the nuances of language and can flag anomalous behavior. I also advise clients to log all interactions with their LLMs and regularly review these logs for signs of manipulation.<\/span><\/p>\n<h3 class=\"ContentText ContentText_variant_h3 ContentText_align_left\" data-testid=\"content-text\" id=\"2. Harden your prompts.\">2. Harden your prompts.<\/h3>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Many LLM vulnerabilities stem from poorly designed prompts. Open-ended prompts that allow for freeform interaction are particularly risky. I advise clients to use highly structured, context-specific prompts that limit the scope of the model&#8217;s responses. Prompts should also include explicit instructions about handling sensitive data and deflecting inappropriate requests.<\/span><\/p>\n<h3 class=\"ContentText ContentText_variant_h3 ContentText_align_left\" data-testid=\"content-text\" id=\"3. Fine-tune your models.\">3. Fine-tune your models.<\/h3>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Off-the-shelf LLMs are trained on broad, generic datasets, which can include biases and vulnerabilities. Fine-tuning the model on your specific domain can not only improve performance but also reduce security risks. By training on curated, sanitized data and incorporating security-specific examples, you can create a model that&#8217;s more resistant to manipulation. I work with clients to develop secure fine-tuning strategies tailored to their unique needs.<\/span><\/p>\n<h3 class=\"ContentText ContentText_variant_h3 ContentText_align_left\" data-testid=\"content-text\" id=\"4. Implement access controls.\">4. Implement access controls.<\/h3>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Not everyone in an organization needs full access to LLMs. Implementing granular access controls, based on the principle of least privilege, can limit the potential impact of a compromised account. I recommend robust authentication and authorization frameworks to secure access to LLMs and other sensitive resources.<\/span><\/p>\n<h3 class=\"ContentText ContentText_variant_h3 ContentText_align_left\" data-testid=\"content-text\" id=\"5. Engage in adversarial testing.\">5. Engage in adversarial testing.<\/h3>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">You can&#8217;t defend against threats you don&#8217;t understand. That&#8217;s why engaging in regular adversarial testing is crucial. This involves attempting to break your own models, using the same techniques an attacker might use. I often conduct adversarial testing for clients, helping them identify and patch vulnerabilities in their LLMs before they can be exploited.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Securing LLMs is an ongoing challenge, and there&#8217;s not a single&nbsp;solution that fits everyone. It requires a proactive, multilayered approach that combines technical controls with robust processes and a security-aware culture.&nbsp;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">I won&#8217;t pretend that we have it all figured out. The truth is, we&#8217;re learning as we go, just like everyone else in this rapidly evolving field. We&#8217;ve had our share of missteps and near misses. But by staying vigilant, collaborating with my clients, and continuously iterating on our practices, we are slowly but surely building a more secure foundation for LLM deployment.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Here is my advice on this: Don&#8217;t underestimate the security implications of LLMs. These models are not just another technology to be bolted onto existing security frameworks. They represent a fundamental shift in how we interact with and secure digital systems. Embracing this shift requires not just new tools and tactics, but a new mindset.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">We need to think beyond traditional perimeter security and static defenses. We need to develop adaptive, AI-driven security that can keep pace with the fluid, conversational nature of LLM interactions. We need to foster a culture of continuous learning and improvement, where every incident is an opportunity to strengthen our defenses.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">It&#8217;s a daunting challenge, but also an exciting one. As a security architect, I&#8217;m energized by the opportunity to help shape the secure deployment of this transformative technology. By sharing our experiences, collaborating across industries, and continually pushing the boundaries of what&#8217;s possible, I believe we can unlock the full potential of LLMs while mitigating their risks.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">It won&#8217;t be easy, and there will undoubtedly be more sleepless nights ahead. But if we approach this challenge with the right mix of caution, creativity, and commitment, I&#8217;m confident we can build a future where LLMs are not just powerful, but also fundamentally trustworthy. And that&#8217;s a future worth losing a little sleep over.<\/span><\/p>\n<p><a href=\"https:\/\/www.darkreading.com\/cybersecurity-operations\/new-mindset-needed-for-large-language-models\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>COMMENTARY As a seasoned security architect, I&#8217;ve started to see<\/p>\n","protected":false},"author":12,"featured_media":3718,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1],"tags":[809],"class_list":["post-3717","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-dark-reading"],"featured_image_urls":{"full":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/new-mindset-needed-for-large-language-models.jpg?fit=1846%2C1043&ssl=1",1846,1043,false],"thumbnail":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/new-mindset-needed-for-large-language-models.jpg?resize=150%2C150&ssl=1",150,150,true],"medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/new-mindset-needed-for-large-language-models.jpg?fit=300%2C170&ssl=1",300,170,true],"medium_large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/new-mindset-needed-for-large-language-models.jpg?fit=640%2C362&ssl=1",640,362,true],"large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/new-mindset-needed-for-large-language-models.jpg?fit=640%2C362&ssl=1",640,362,true],"1536x1536":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/new-mindset-needed-for-large-language-models.jpg?fit=1536%2C868&ssl=1",1536,868,true],"2048x2048":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/new-mindset-needed-for-large-language-models.jpg?fit=1846%2C1043&ssl=1",1846,1043,true],"chromenews-featured":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/new-mindset-needed-for-large-language-models.jpg?fit=1024%2C579&ssl=1",1024,579,true],"chromenews-large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/new-mindset-needed-for-large-language-models.jpg?resize=825%2C575&ssl=1",825,575,true],"chromenews-medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/new-mindset-needed-for-large-language-models.jpg?resize=590%2C410&ssl=1",590,410,true]},"author_info":{"display_name":"Dark Reading","author_link":"https:\/\/ddi.mohflo.net\/index.php\/author\/darkreading\/"},"category_info":"<a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/uncategorized\/\" rel=\"category tag\">Uncategorized<\/a>","tag_info":"Uncategorized","comment_count":"0","jetpack_featured_media_url":"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/new-mindset-needed-for-large-language-models.jpg?fit=1846%2C1043&ssl=1","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/3717","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/comments?post=3717"}],"version-history":[{"count":0,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/3717\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media\/3718"}],"wp:attachment":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media?parent=3717"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/categories?post=3717"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/tags?post=3717"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}