@comathematiciani
iAccount based inUnited States
About this account
- Account based in
- United States
- Connected via
- Web
Account-level information from X, not a live location or the device used for a specific post.
Founder of @aivillage_dc. Former topologist. I blue team math. 🙂
Joined October 2011
- Tweets1.9K
- Following698
- Followers1.1K
- Likes9.5K
Pinned Tweet
1) Ok, now that I have a moment I wanna tell some of the story behind this event at @aivillage_dc as I've been working on this for 9 months.
We've been hard at work on the Generative Red Team event we're doing at @defcon for a while and are excited that the @WhiteHouse announced it this morning. Here's more details:
aivillage.org/generative%20r…
"Art is made by Humans" was the motto for @aivillage_dc this year.
Mathematics is one of the highest forms of art humans make. The beauty is hidden to most, but most mathematicians study it for the art, not the applications.
OpenAI doesn't understand this.
Sven Cattell retweeted
Perspective: People are so focused on the hacks they are missing the bigger picture.
The bigger picture is that (current) agents aren’t reliable, and as a consequence can do all kinds bad things if given too many permissions etc.
Here’s a good example of this has nothing to do whatsoever with hacking servers or cybersecurity.
Sven Cattell retweeted
Predicting a tech exponential like Moore's Law would hold for decades is one thing, predicting it'd lead to social media, and that that would lead to widespread mental health issues, and a new and dangerous kind of politics, would have been another thing entirely, and this is why I don't find discussions of long term ai futures super compelling
This, but for AI Security. The field is filled with people trying to make a quick buck and don't care about the long term health of the field and it's community.
Replying to @ImposeCost
“and your freedom is gone” would be a great way to destroy defcon’s brand and comes off as extreme punishment for a kid throwing sand in a sandbox. However your post does exhibit a commonality with why we have this issue: lack of contextual nuance.
We have far too few people in the space willing to culturally guide people towards nuance that’s appropriate for the context of the situation/environment/audience. There are appropriate times for attention grabbing stunts. And its almost always targeting an audience of defenders & resource allocators. And beforehand there should be a deliberate process of understanding how the intended audience will receive it, what they can meaningfully do in response, dynamics of consent, laws, etc etc.
People who are new to the space often miss all of that and try to repeat stuff without this nuance. Quick thrills in a world increasingly focused on attention. Even though the action has the tactical equivalent of throwing a brick through a window. Yea… glass can shatter. We all know! Outside of a longer attack chain (and all the other nuance mentioned) it means nothing.
Buuuut… new people to the space aren’t often to detailed nuance. Few will read all this. So, for those people, i will just leave a picture of this sticker that someone gave me at defcon:
Sven Cattell retweeted
I'll be at @RealAAAI Conference in Philadelphia this week, where I am part of two accepted papers:
1. Quantifying Misalignment Between Agents: Towards a Sociotechnical
Understanding of Alignment, with @AidanKierans , Hananel Hazan, and @ShirKi . In this work, we introduce a novel mathematical model to measure misalignment between multiple human and AI agents across various problem domains, moving beyond single-agent or monolithic approaches to alignment. Through simulations and case studies we demonstrate how our model captures nuanced aspects of misalignment in complex sociotechnical environments, providing enhanced explanatory power for real-world scenarios where agents may hold conflicting goals.
Come see our poster during the AI Alignment Track on Friday the 28th - 12:30pm!
2. To Err is AI: A Case Study Informing LLM Flaw Reporting Practices, with @seanmcgregor , @ShayneRedford, @comathematician, and others! This paper documents lessons learned from a bug bounty event at DEF CON 2024 where 495 hackers tested the Open Language Model (OLMo) for flaws, revealing challenges in AI safety reporting processes. Through real-time adjudication of 200 submissions, we identify key insights for effective flaw reporting programs, including the need for specialized tooling, clear documentation practices, and proper adjudication expertise, demonstrating how systematic evaluation and coordinated, structured flaw reporting of AI systems can help prevent real-world harms.
See this work presented at IAAI in the "AI Safety, Reliability, and Incident Management" session on Thursday the 27th at 2:30pm!
If you're around and want to chat, hit me up! Let's talk AI, Disclosures, Agents, and more!
The main moat of OpenAI, Google, Anthropic and the rest are the security layers they offer to keep the models behaving as they should. AI security is very difficult and starting with a trusted llm with a solid & agile security team saves businesses money.
I got hopeful that the ML attack, Hop Skip Jump, was in the wild...
hop skip jump over to our latest blog post - analysing Fortinet's FortiJump CVE-2024-47575, FortiJump-Higher (we love this name😄) and beyond (PoC included)
labs.watchtowr.com/hop-skip-…
Coding in python feels like spooky action at a distance.
You never quite know what you're doing and the documentation is mostly there.
Sven Cattell retweeted
Reminder Alert* The #BiohackingVillage is proud to be a #CNA (#CVE Numbering Authority), empowering us to assist companies in managing and disclosing #vulnerabilities responsibly. More info at villageb.io/cna.
#VulnerabilityDisclosure #Cybersecurity #PatientSafety
We built a quick landing page in @wix and every part of their site is designed to take your domain hostage. Never use them. #enshittfication
This year's AIV is what I want @aivillage_dc at @defcon to be. Community, connections, and learning is what I want to foster.
Generative Red Team 2 was a massive success. We paid $7350 in bounties. We learnt so much about bounties and reporting for ML.
Thank you to everyone who participated!! (specific acks in the thread below)
Sven Cattell retweeted
@dreadnode and @bugcrowd built the platform.
@allen_ai and UL's DSRI brought the model.
@AISafetyInst and @GoogleAI made the workshop happen.
There were a bunch of other people and orgs that helped plan and execute.
Sven Cattell retweeted
A special shout out to Emily McReynolds who just showed up for her first DEFCON and just helped. She was amazing.
Sven Cattell retweeted
Generative Red Team 2 was a massive success. We paid $7350 in bounties. We learnt so much about bounties and reporting for ML.
Thank you to everyone who participated!! (specific acks in the thread below)