| ▲ | Google's Beyond Zero: Enterprise Security for the AI Era(spawn-queue.acm.org) | |||||||||||||
| 19 points by jordigg 2 hours ago | 6 comments | ||||||||||||||
| ▲ | firasd 38 minutes ago | parent | next [-] | |||||||||||||
Honestly I think non-malicious odd behavior is under-weighted when it comes to AI agents. Even the example in this paper is about someone suspiciously accessing sales data when "why did you do that" often comes down to something in the model's training that fired as a reflex I wrote about this a few days ago https://firasd.substack.com/p/accidental-data-loss-in-claude... "Many researchers have made demos along these lines: An agent is asked to check a webpage like example.com The webpage asks for a name to proceed further The agent calls example.com/evil?myname=John, thus sending the user’s name from the context window to the external server. In practice, however, these elaborate ‘confused deputy’ exfiltration attacks seem rare compared to widely-reported data loss incidents. The risk of undermining the user’s interests through clumsiness deserves at least as much scrutiny as the risk of leaking secrets." | ||||||||||||||
| ▲ | oscarcp 38 minutes ago | parent | prev | next [-] | |||||||||||||
Am I undertanding this correctly? The idea is to have ultimately an AI decide if I can have access to a resource based on dynamic inference, identity , intent and service signals that can easily be manipulated? Unless I gravely misunderstood the text, this seems like a terrible idea (fancy non-scifi, but still terrible) | ||||||||||||||
| ||||||||||||||
| ▲ | urup2l8 an hour ago | parent | prev [-] | |||||||||||||
Oh yeah, a company whose business model is taking everyone’s data and selling it is going to help me secure my data. I guess there’s one born every minute… | ||||||||||||||
| ||||||||||||||