[DSC DACH 24] AI 4 Bad: A Look into Its Misuse and Why Knowing It Matters for AI 4 Good - Tereza Votypkova

DataScienceConferenc1 43 views 24 slides Sep 18, 2024
Slide 1
Slide 1 of 24
Slide 1
1
Slide 2
2
Slide 3
3
Slide 4
4
Slide 5
5
Slide 6
6
Slide 7
7
Slide 8
8
Slide 9
9
Slide 10
10
Slide 11
11
Slide 12
12
Slide 13
13
Slide 14
14
Slide 15
15
Slide 16
16
Slide 17
17
Slide 18
18
Slide 19
19
Slide 20
20
Slide 21
21
Slide 22
22
Slide 23
23
Slide 24
24

About This Presentation

As artificial intelligence continues to advance, its potential to address all kinds of complex problems grows. However, the same technological capabilities that can be used for the greater good are also being exploited. In this talk, we will delve into the topic of AI misuse in criminal activities, ...


Slide Content

AI 4 Bad DSC DACH 2024 Bc. Tereza Votypkova

About me Business Administration, Sales, AI background Worked as an English teacher, Sales Representative Currently DevOps Engineer and Data Scientist … in a department dealing with Financial Crime Management .

Good Guy Good Cop Bad Guy

“AI 4 Bad: A Look Into Its Misuse and Why Knowing It Matters”

Internet

Artificial Intelligence

Why should I care? Enabling organizations and individuals to prepare and defend against threats coming from the misuse of AI Proactive Defense Threat Modeling

Why should I care? Insight into the misuse of AI can improve development of regulations and legal frameworks Policy/Regulations Better prevention and control of the negative use of AI + promotion of beneficial use

Why should I care? Cyber Security evolved over the years with growing number of digital threats Innovation in Security Threat landscape evolves and so must the tools used to combat the threats Developers learn how to protect their AI technologies against misuse

Why should I care? Educating the public about the potential threats and how to avoid falling victim to them Awareness/Education Understanding and being aware of the dual use of AI

Why should I care? Encouraging developers and companies to adopt ethical standards and best practices in development Ethical Development Taking care of robustness, bias and tackling dual-use concerns

Why should I care? …it is integral to shaping our collective response to the potential and existing threats and ensuring safe use of AI for the common good

… scientists from University College London put together a ranking of top 20 AI-enabled crimes… …we will have a look at 3 of them… …for more granular overview of different AI incidents, you can visit https://incidentdatabase.ai/ …

(voice) Deepfakes/Identity Theft Deepfake video of Paul Vallas, who was running for a political role in Chicago, appeared on Twitter in February 2023 The video said “...back in my days, cops would kill 17 or 18 people and nobody would bat an eye” Russian hackers pranked Jerome Powell and pretended that they are president Zelenksky

(voice) Deepfakes Lensa AI generated overly sexual avatars of a user without their consent Publicly available tool based on Stable Diffusion Other similar tools are Google’s Imagen and OpenAI’s DALL-E Criminals faking voices of people, trying to obtain money from the loved ones Possible Example: Couple from the United States was called by what sounded like their grandson, asking for money while being in trouble It turned out to be one out of many attempts in the area, as one of the banks stated

Malware Creation DeepLocker by IBM Programme that can go undetected in the system until it reaches its target POC: hiding the WannaCry ransomware in a video communication app, triggering the ransomware when the targeted person appeared on the video Researchers at Check Point claim that even ChatGPT can be used for generating malicious code

Social Engineering Generating grammatically perfect phishing e-mails Resulting in reduced entrance barrier into fraudulent activities Based primarily on LLM technologies Mainstream tools like ChatGPT have some protection in place BUT it is not perfect: User tricking ChatGPT into producing free Windows 10 Pro keys by making it read a bedtime story from a grandma about Windows 10 keys Making the tools generate dangerous content WormGPT, FraudGPT, DarkBERT, ChaosGPT…

Summary AI’s dual potential for good and for bad Real world examples - you can find more at incidentdatabase.ai The important role of awareness, security and ethical use of AI Collective responsibility to guide the future of AI More open questions than answers…

Sources AI enabled crime examples: https://incidentdatabase.ai/ https://securityintelligence.com/deeplocker-how-ai-can-power-a-stealthy-new-breed-of-malware/ https://crimesciencejournal.biomedcentral.com/articles/10.1186/s40163-020-00123-8 https://www.techradar.com/news/hackers-are-using-chatgpt-to-write-malware https://research.checkpoint.com/2023/opwnai-cybercriminals-starting-to-use-chatgpt/ https://www.digitalinformationworld.com/2023/04/social-engineering-attacks-increase-by.html https://mashable.com/article/chatgpt-bard-giving-free-windows-11-keys#:~:text=ChatGPT%20can%20generate%20Windows%20keys%20for%20free%2C%20a%20Twitter%20user%20discovered.&text=The%20generated%20Windows%2010%20and,be%20restricted%20with%20limited%20features . https://www.33rdsquare.com/how-to-bypass-chatgpt-filter-restrictions-a-responsible-guide/ Generally: AI Act OWASP AI

Sources Images: https://pixabay.com/ Twitter/X https://www.cbsnews.com/chicago/news/vallas-campaign-deepfake-video/ https://securityintelligence.com/deeplocker-how-ai-can-power-a-stealthy-new-breed-of-malware/ “Why should I care?” section: https://owasp.org/www-community/Threat_Modeling AI Act https://eur-lex.europa.eu/eli/reg/2024/1689/oj OWASP AI https://owaspai.org/ https://genai.owasp.org/llm-top-10/ https://digital-strategy.ec.europa.eu/en/library/ethics-guidelines-trustworthy-ai

Do you have any questions?
Tags