正在加载视频...

视频加载失败

👼 BASICS OF ETHICAL HACKING – CORE TRAINING 😈 🔰 Learn key topics like CEH overview, hacking concepts, security threats, attack types, and building a safe hacking lab. 🔗 LINK:

12,232 次观看 • 5 个月前 •via X (Twitter)

0 条评论

暂无评论

原始帖子的评论将显示在这里

相关视频

Arena intern and UCLA PhD candidate, Hengguang Zhou, introduces Trace-and-Amplify (TA), a framework for collecting training-time reward-hacking trajectories at scale without hacking instructions. Monitors trained and evaluated on prompt-elicited hacking trajectories can achieve high detection accuracy, but often fail to transfer to training-time reward-hacking trajectories that emerge during RL without hacking instructions. Trace-and-Amplify enables scalable collection of these training-time trajectories, producing monitors that generalize much better to real and held-out hacking types. Detection accuracy 59.98% (PE-trained) → 90.16% (TA-trained) compared to 97.1% on prompted hacks → 28.0% on training-time hacks. 0:00 – OpenAI's ExploitGym cyberattack benchmark exploit 1:04 – Goodhart's Law and the CoastRunners boat-racing hack (2016) 2:04 – Gaming the evaluator: the robot-hand grasping example (2017) 3:10 – Reward hacking in code generation: hard-coding, test-rewriting, skipping eval 4:20 – A standard defense: reward-hacking monitors 4:58 – Monitor architectures: zero-shot LLMs, fine-tuned BERT, hidden-state probes 6:11 – Where monitor training data comes from today: prompted hacks 7:03 – The core question: do prompted hacks represent real hacks? 7:35 – Why this matters: RL post-training is the standard recipe for frontier models 8:20 – Why nobody's checked this before (hacking is rare, labeling isn't scalable) 9:23 – Introducing the method: Trace-and-Amplify 9:49 – The Tracer: a contradictory unit test that locates evaluation-gaming 10:50 – Amplify: collecting hacking rollouts at scale during RL training 11:32 – Experiment setup: Qwen2.5-Coder, DeepSeek-Coder, LeetCode/TACO 12:16 – Finding #1: prompt-trained monitors don't transfer to real hacks 14:40 – Can strong zero-shot judges (GPT-4.1, o4-mini) do better? 15:48 – Finding #2: monitors trained on real hacks generalize much better to unseen hacks 17:04 – Ruling out artifacts introduced by the method 17:55 – Why the gap? Real hacking is more hidden than prompted hacking 20:05 – Three takeaways, limitations, and future work

Arena.ai

31,243 次观看 • 4 天前

Must watch clip right here. 2019. Ted Lieu and former Democrat Congresswoman Jane Harman participate in a panel during the annual DEF CON conference. DEF CON is the world's largest hacker convention. Hackers, computer security experts, intelligence community members, and many others get together to discuss ideas, threats, and to hold hacking contests. Jane Harman served nine terms in Congress, sat on all the major security committees, and was the ranking member of the House Intelligence Committee. She also is President of the Woodrow Wilson think tank and sits on numerous security advisory boards. Harman: The 2020 election is not secure. At least a third of all voting machines are totally vulnerable. Lieu and Harman were there because DEF CON had recently held a "voting village" where hackers attempted (and succeeded) in hacking into our voting machines. Teenagers were even able to hack into some machines. Ted Lieu urged the hackers to meet with media and to speak out about how vulnerable our voting machines are. Lieu said the public needed to know how vulnerable our elections are. Lieu also criticized McConnell for not passing election security legislation that would require paper trails for all votes. 😂 Democrats and the media regularly spoke about the vulnerabilities of our elections, all the way up until the 2020 election. Immediately after the 2020 election it became forbidden to question the security of our elections. They all just began reciting the talking point "It was the most secure election ever."

MAZE

105,651 次观看 • 26 天前