As artificial intelligence continues to advance, its potential to address all kinds of complex problems grows. However, the same technological capabilities that can be used for the greater good are also being exploited. In this talk, we will delve into the topic of AI misuse in criminal activities, ...
As artificial intelligence continues to advance, its potential to address all kinds of complex problems grows. However, the same technological capabilities that can be used for the greater good are also being exploited. In this talk, we will delve into the topic of AI misuse in criminal activities, exploring real-world examples and learning about the techniques behind these attacks. From deepfake scams and automated hacking to AI-driven fraud and beyond, we will shed light on the darker side of AI innovation and understand why knowing it is important for using AI for good!
Size: 5.76 MB
Language: en
Added: Sep 18, 2024
Slides: 24 pages
Slide Content
AI 4 Bad DSC DACH 2024 Bc. Tereza Votypkova
About me Business Administration, Sales, AI background Worked as an English teacher, Sales Representative Currently DevOps Engineer and Data Scientist … in a department dealing with Financial Crime Management .
Good Guy Good Cop Bad Guy
“AI 4 Bad: A Look Into Its Misuse and Why Knowing It Matters”
Internet
Artificial Intelligence
Why should I care? Enabling organizations and individuals to prepare and defend against threats coming from the misuse of AI Proactive Defense Threat Modeling
Why should I care? Insight into the misuse of AI can improve development of regulations and legal frameworks Policy/Regulations Better prevention and control of the negative use of AI + promotion of beneficial use
Why should I care? Cyber Security evolved over the years with growing number of digital threats Innovation in Security Threat landscape evolves and so must the tools used to combat the threats Developers learn how to protect their AI technologies against misuse
Why should I care? Educating the public about the potential threats and how to avoid falling victim to them Awareness/Education Understanding and being aware of the dual use of AI
Why should I care? Encouraging developers and companies to adopt ethical standards and best practices in development Ethical Development Taking care of robustness, bias and tackling dual-use concerns
Why should I care? …it is integral to shaping our collective response to the potential and existing threats and ensuring safe use of AI for the common good
… scientists from University College London put together a ranking of top 20 AI-enabled crimes… …we will have a look at 3 of them… …for more granular overview of different AI incidents, you can visit https://incidentdatabase.ai/ …
(voice) Deepfakes/Identity Theft Deepfake video of Paul Vallas, who was running for a political role in Chicago, appeared on Twitter in February 2023 The video said “...back in my days, cops would kill 17 or 18 people and nobody would bat an eye” Russian hackers pranked Jerome Powell and pretended that they are president Zelenksky
(voice) Deepfakes Lensa AI generated overly sexual avatars of a user without their consent Publicly available tool based on Stable Diffusion Other similar tools are Google’s Imagen and OpenAI’s DALL-E Criminals faking voices of people, trying to obtain money from the loved ones Possible Example: Couple from the United States was called by what sounded like their grandson, asking for money while being in trouble It turned out to be one out of many attempts in the area, as one of the banks stated
Malware Creation DeepLocker by IBM Programme that can go undetected in the system until it reaches its target POC: hiding the WannaCry ransomware in a video communication app, triggering the ransomware when the targeted person appeared on the video Researchers at Check Point claim that even ChatGPT can be used for generating malicious code
Social Engineering Generating grammatically perfect phishing e-mails Resulting in reduced entrance barrier into fraudulent activities Based primarily on LLM technologies Mainstream tools like ChatGPT have some protection in place BUT it is not perfect: User tricking ChatGPT into producing free Windows 10 Pro keys by making it read a bedtime story from a grandma about Windows 10 keys Making the tools generate dangerous content WormGPT, FraudGPT, DarkBERT, ChaosGPT…
Summary AI’s dual potential for good and for bad Real world examples - you can find more at incidentdatabase.ai The important role of awareness, security and ethical use of AI Collective responsibility to guide the future of AI More open questions than answers…
Sources AI enabled crime examples: https://incidentdatabase.ai/ https://securityintelligence.com/deeplocker-how-ai-can-power-a-stealthy-new-breed-of-malware/ https://crimesciencejournal.biomedcentral.com/articles/10.1186/s40163-020-00123-8 https://www.techradar.com/news/hackers-are-using-chatgpt-to-write-malware https://research.checkpoint.com/2023/opwnai-cybercriminals-starting-to-use-chatgpt/ https://www.digitalinformationworld.com/2023/04/social-engineering-attacks-increase-by.html https://mashable.com/article/chatgpt-bard-giving-free-windows-11-keys#:~:text=ChatGPT%20can%20generate%20Windows%20keys%20for%20free%2C%20a%20Twitter%20user%20discovered.&text=The%20generated%20Windows%2010%20and,be%20restricted%20with%20limited%20features . https://www.33rdsquare.com/how-to-bypass-chatgpt-filter-restrictions-a-responsible-guide/ Generally: AI Act OWASP AI
Sources Images: https://pixabay.com/ Twitter/X https://www.cbsnews.com/chicago/news/vallas-campaign-deepfake-video/ https://securityintelligence.com/deeplocker-how-ai-can-power-a-stealthy-new-breed-of-malware/ “Why should I care?” section: https://owasp.org/www-community/Threat_Modeling AI Act https://eur-lex.europa.eu/eli/reg/2024/1689/oj OWASP AI https://owaspai.org/ https://genai.owasp.org/llm-top-10/ https://digital-strategy.ec.europa.eu/en/library/ethics-guidelines-trustworthy-ai