Loading video...

Video Failed to Load

Go Home

"All untrusted third-party data is now executable malware.” Sam Watts of Lakera AI discusses the challenges of securing LLM deployments against vulnerabilities like prompt injections and jailbreaks, especially in an evolving threat landscape.

470,622 views • 1 year ago •via X (Twitter)

27 Comments

Maya World's profile picture
Maya World1 year ago

@SamuelDWatts @LakeraAI "Untrusted third-party data is now executable malware." Bold, but absolutely correct for LLMs.

FAR.AI's profile picture
FAR.AI1 year ago

@LakeraAI Follow us for AI safety insights And watch the full video

Seb⚡'s profile picture
Seb⚡8 months ago

@SamuelDWatts @LakeraAI Spot on. Treating all third‑party inputs as potentially hostile is the only sane default in LLM security. Prompt injections and jailbreaks aren’t edge cases anymore—they’re the threat landscape. Secure-by-design needs to become the norm, not the exception.

Simon's profile picture
Simon1 year ago

@SamuelDWatts @LakeraAI Thats a little "FAR" fetched

john carter's profile picture
john carter8 months ago

@SamuelDWatts @LakeraAI 🤩

MagicKall's profile picture
MagicKall1 year ago

@SamuelDWatts @LakeraAI Absolutely. Treat every user string like untrusted code. Sanitising and gating inputs can stop most prompt injection attempts — we found ~70% of exploits die with a simple filter. How are you layering defences today? ☺

Dennis's profile picture
Dennis9 months ago

@SamuelDWatts @LakeraAI Add CBDC and digital ID and it becomes a (blackhat) hacker’s paradise.

Milad's profile picture
Milad8 months ago

@SamuelDWatts @LakeraAI Critical security awareness for AI systems.

Rishabh's profile picture
Rishabh10 months ago

This is the exact wake-up call the industry needs. We're rushing to integrate LLMs into production without thinking about attack surface. Every RAG system, every agent with web access, every chatbot reading PDFs - all potential entry points. Prompt injection isn't a bug, it's a fundamental architectural flaw we haven't solved yet.

chav's profile picture
chav7 months ago

@SamuelDWatts @LakeraAI All spam posts on x need to go #nospam

Lakera AI's profile picture
Lakera AI1 year ago

@SamuelDWatts @SamuelDWatts 👏👏

Idan Zeidman's profile picture
Idan Zeidman8 months ago

@SamuelDWatts @LakeraAI "Executable malware" hits hard, what's your go-to for gating third-party data before it hits the LLM?

Shreyas's profile picture
Shreyas8 months ago

@SamuelDWatts @LakeraAI AI prompt engg is future

Useless Eater's profile picture
Useless Eater9 months ago

@SamuelDWatts @LakeraAI Interesting. This may cause traditionally-coded websites to also become AI-driven in order to protect themselves against AI-based hacking.

Norbert's profile picture
Norbert10 months ago

@SamuelDWatts @LakeraAI @grok make transcript of that video

Gator Stephens the Pilot of the 4 Winds's profile picture
Gator Stephens the Pilot of the 4 Winds11 months ago

@SamuelDWatts @LakeraAI Thoughts @BrianRoemmele?

extemporaneous improvident marv, always will be's profile picture
extemporaneous improvident marv, always will be1 year ago

@SamuelDWatts @LakeraAI to be honest this was already essentially the case even absent an LLM if you're presuming it's malware simply because it's untrusted, that doesn't change whether or not an LLM could be the target vector

nodespectre's profile picture
nodespectre1 year ago

@SamuelDWatts @LakeraAI I do think we should be cautiuous with our data being given to china or india, those people could easily exploit us and give themselves a very large very big advantage

Giovanni Motta's profile picture
Giovanni Motta1 year ago

@SamuelDWatts @LakeraAI good work

Bent Preben Nielsen's profile picture
Bent Preben Nielsen8 months ago

@SamuelDWatts @LakeraAI Men da ikke svære at afsløre.

richard wendling's profile picture
richard wendling8 months ago

@SamuelDWatts @LakeraAI whats on his arm?

Endre Tolnai's profile picture
Endre Tolnai9 months ago

@SamuelDWatts @LakeraAI Ki fogja ezekért vállalni a felelősséget?

Himanshu Kumar's profile picture
Himanshu Kumar9 months ago

@SamuelDWatts @LakeraAI Absolutely, Farai, that's a scary thought, but a crucial point to ponder, isn't it?

Shp Square's profile picture
Shp Square1 year ago

@SamuelDWatts @LakeraAI

PWG | PawanGrowth🎯's profile picture
PWG | PawanGrowth🎯1 year ago

@SamuelDWatts @LakeraAI Very thanks for this valuable content.

Lambda Rick 🏴‍☠️/acc's profile picture
Lambda Rick 🏴‍☠️/acc1 year ago

@SamuelDWatts @LakeraAI not if u run LLM in browser. it doesnt get execute permission there but does get GPU

The Energy King's profile picture
The Energy King1 year ago

@SamuelDWatts @LakeraAI You look jewish

Related Videos

LLM Defender Synapsec Subnet 14 powered by $TAO on Bittensor is tackling some seriously critical issues in AI security 🛡. The risks of prompt injection attacks, data leaks, malware - this stuff is no joke. If left unchecked, it could really fu¢k up the progress and potential of AI. But that's where @SYNAPSEC_AI and their badass team come in. They're not just building another firewall; they're pioneering a whole new approach to AI security. By leveraging the decentralized intelligence of the Bittensor network, they're creating a multi-layered, adaptive defense system that can evolve as fast as the threats do. The fact that they're focussing on prompt injection attacks first shows they've got their priorities straight. As the article explains, these attacks can trick AI into doing all sorts of shady shit, from leaking sensitive data to straight up breaking the law. It's a hacker's wet dream 💦 come true if we don't put a stop to it. Here's how Synapsec can tackle prompt injection threats in AI systems: 1. Protection Importance: As companies increasingly use LLMs, Synapsec will prioritize protecting client data from prompt injection attacks that risk exposing sensitive information. 2. Direct Prompt Injection: Synapsec will implement strict input validations to prevent malicious prompt injections that could manipulate the AI system. 3. Indirect and Stored Prompt Injection: Synapsec will sanitize external data sources to ensure security and prevent indirect prompt injections. 4. Prompt Leaking Attacks: Techniques like shortening user prompts and adding system-controlled information will be used to avoid leakage of internal prompt details. 5. Continuous Improvement: Synapsec will continually enhance their security practices to address evolving prompt injection threats, ensuring protection for client systems. The security of client AI applications as LLM adoption grows will be a massive industry. But Synapsec is coming out swinging with their analyzer engines and Bug Bounty program. They're not just waiting for attacks to happen; they're proactively hunting down vulnerabilities and bringing in the best minds in cybersecurity to fortify their defenses. The beauty of it all is that it's powered by $TAO and the Bittensor ecosystem. This isn't just another corporate cybersecurity gig; it's a decentralized, community-driven effort to safeguard the future of AI. By aligning incentives through the $TAO token, they're ensuring that everyone has a stake in keeping these systems secure. So yeah, I'm stoked about what Subnet 14 is doing. It's not just important; it's absolutely essential if we want AI to reach its full potential without being hijacked by bad actors. These guys are the real dwal, working behind the scenes to keep our AI safe and sound. And for anyone who's still sleeping on $TAO and Bittensor, wake the fu¢k up. This is where the real innovation in AI and blockchain is happening. With subnets like LLM Defender leading the charge, $TAO isn't just another crypto play; it's the backbone of a revolution in decentralized AI. So keep your eyes peeled, folks. Subnet 14 and Synapsec are just getting started, and they've got the vision, the tech, and the balls to take AI security to the next level. In a world where AI is increasingly weaving into the fabric of our lives, their work couldn't be more critical. I, for one, am grateful that they're on our side, fighting the good fight. 🙏💪🔒

Andy ττ

10,745 views • 2 years ago

Scale alone is not enough for AI data. Quality and complexity are equally critical. Excited to support all of these for LLM developers with Snorkel AI Data-as-a-Service, and to share our new leaderboard! — Our decade-plus of research and work in AI data has a simple point: scale alone is not enough. AI success is all about the quality, complexity, and distribution of data—in addition to volume. We’re excited to be powering leading LLM developers with Snorkel AI Expert Data-as-a-Service, our white glove service for custom, expert-level AI datasets—and to now preview some of what we’re building via our new Expert Data Leaderboard (🔗 in 🧵) + upcoming OSS dataset releases! Snorkel Expert Data-as-a-Service is built to meet the rapidly evolving data needs of the agentic AI world—where success is built on the quality, complexity, and distribution of datasets, in addition to size and scale. This kind of high-quality, frontier AI data can only come from a union of technology and human expertise. With Snorkel Expert Data-as-a-Service, we’re powering frontier LLM developers across agentic, expert knowledge, reasoning, coding, multi-modal, and other task types via the combination of these two key components: - (1) The Snorkel Expert Network: A global team of subject matter experts focused wholly on specialized knowledge–spanning thousands of topics in STEM/academic, vertical/professional, and consumer/lifestyle domains. - (2) Snorkel AI Data Development Platform: Our unique programmatic data curation and quality control platform, accelerating and improving expert authoring and review through principled techniques developed over the last decade of R&D. Now: we’re incredibly excited to showcase some of the power of Snorkel Expert Data-as-a-Service via the new Snorkel Leaderboard—putting frontier models to the test in complex, agentic, and reasoning settings inspired by real industry scenarios (not esoteric puzzles)! We’ll be releasing new leaderboards and accompanying expert-verified open source datasets (coming soon!) regularly. To start, we’re sharing three initial ones in preview: - SnorkelFinance: Q&A over financial documents requiring agentic tool-calling and reasoning - SnorkelUnderwrite: Agentic insurance tasks requiring industry-specific reasoning and tool use - SnorkelSequences: Mathematical tasks requiring compositional multi-step reasoning

Alex Ratner

495,851 views • 1 year ago