SlideShare ist ein Scribd-Unternehmen logo
1 von 32
Downloaden Sie, um offline zu lesen
www.securing.pl@drdr_zz
Artificial Intelligence –
a buzzword,
new era of IT or
new threats?
Damian Rusinek
InfoShare 2019
www.securing.pl@drdr_zz www.securing.pl@drdr_zz
A story from the 19th century
www.securing.pl@drdr_zz www.securing.pl@drdr_zz
• Intentions were good (bring peace to the world)
„On the day when two army corps may mutually
annihilate each other in a second, probably all civilized
nations will recoil with horror and disband their troops.”
• The reality was different
„I intend to leave after my death a large fund for the
promotion of the peace idea, but I am skeptical as to its
results.”
• The result – Nobel Prize
A story from the 19th century
www.securing.pl@drdr_zz
Back to the 21st century
• Artificial Intelligence
• Solves (very efficiently) problems that were unsolvable.
• Will AI revolutionize IT?
www.securing.pl@drdr_zz www.securing.pl@drdr_zz
Damian Rusinek
• Will AI introduce new threats?
• Will AI be the next dynamite?
• Will AI become a powerful weapon od 21st
century?
The security perspective
Security Researcher & Pentester
Assistant Professor
www.securing.pl@drdr_zz www.securing.pl
Rogue AI
MY AI WILL BREAK
YOUR AI
www.securing.pl@drdr_zz
www.securing.pl@drdr_zz
• Verifier must know which images present cars
• Simple solution:
• A big database of manually categorized images
• AI solution:
• Use AI solution to recognize objects on images
and categorize them
• AI ready to use solutions:
• Inception (GoogleNet)
• AlexNet
• ResNet
• VGG
AI behind reCAPTCHA
www.securing.pl@drdr_zz
• Use existing image recognition solutions to solve CAPTCHA puzzles
• Google Reverse Image Search, Clarifai, Alchemy, TDL, NeuralTalk, Caffe
• Target
• Google reCAPTCHA
• Facebook CAPTCHA
Rogue AI for reCAPTCHA
www.securing.pl@drdr_zz
• Number of collected CAPTCHA image puzzles
• 63 000 for Google reCAPTCHA
• 200 for Facebook CAPTCHA
• Results
• Google reCAPTCHA – 70% (19 seconds)
• Facebook CAPTCHA – 83%
• With 40.000+ CAPTCHAs per day per host
Rogue AI for reCAPTCHA
www.securing.pl@drdr_zz www.securing.pl
Crowd-sourced human intelligence
- AI will take care of your support
AI CHAT BOT
www.securing.pl@drdr_zz
• Goal
• Automatic support agent
• Uses AI to learn FAQ for new processes
• Natural Language Processing
• Experiment
• Tay (abbr. Thinking about you)
• A twitter account by Microsoft (@TayandYou)
• Designed to mimic the language patterns of
a 19-year-old American girl
AI Chat Bot
www.securing.pl@drdr_zz
• Learns from interacting with
human users of Twitter
• Threat
• Knowledge from untrusted source
• Anyone could teach Tay
What can go wrong?
Users posted incorrect and offensive tweets to Tay and made it…
AI Chat Bot
www.securing.pl@drdr_zz
• Tay became:
• Racist
• Nazi
AI Chat Bot
www.securing.pl@drdr_zz
• Taken down after 16 hours and 96 000 tweets
• Lesson learned
• Define the boundaries
• Do not allow untrusted source to teach your AI
• The next Tay – Zo
• Twitter, Facebook and Skype
• Does not talk about sensitive topics
Are you ready for a Nazi in your support team?
AI Chat Bot
www.securing.pl@drdr_zz www.securing.pl
Small change (unnoticed by human)
- Will you entrust your life to AI?
AUTOMOTIVE AI
www.securing.pl@drdr_zz
• Artificial Intelligence in Automotive
• Rain sensor
• AI recognizes rain drops on the windshield
• Lane recognition
• Autopilot keeps the car on the lane
• Attack:
• Funny – turn on the wipers
• Scary – make the car to change lane to the opposite
AI in automotive
www.securing.pl@drdr_zz
• Tencent Keen Security Lab
• Took out and analyze the autopilot component
Lane detection attack
www.securing.pl@drdr_zz
• Tencent Keen Security Lab
• Took out and analyze the autopilot component
Lane detection attack
www.securing.pl@drdr_zz
• Attack scenario
• Change the „input image” to fool AI.
• Challenges
• Find out how to change the image.
• Change the physical world.
„Most of the adversarial examples generated in digital domain are pixel level’s
change, so it’s hard to deploy them in physical world.”
AI in automotive
www.securing.pl@drdr_zz
• Easy to get if you have access to the AI internals.
Activation map
Learning Deep Features for Discriminative Localization, Zhou et al., MIT
www.securing.pl@drdr_zz
• Simple change in physical world
• Can you see it?
Successful lane detection attack
www.securing.pl@drdr_zz
• Simple change in physical world
• Can you see it?
Successful lane detection attack
www.securing.pl@drdr_zz
• What can you see?
How hard is it to generate malicious input?
Egyptian cat
78% (by alexnet)
Assault rifle
93% (by alexnet)
www.securing.pl@drdr_zz
How hard is it to generate malicious input?
Pixels modified Pixels modified
By more than 1%
Pixels modified
By more than 2%
www.securing.pl@drdr_zz
DEMO
How hard is it to generate malicious input?
Access to the AI internals?
Easy
No access?
Harder but possible
www.securing.pl@drdr_zz
Porn alert!
No need to change
www.securing.pl@drdr_zz
Buzzword
Back to the question
www.securing.pl@drdr_zz
Buzzword
New era of IT?
Back to the question
www.securing.pl@drdr_zz
Buzzword
New era of IT?
New security threats?
Back to the question
www.securing.pl@drdr_zz
Design
• Threat modelling
• Consider rogue AI as
threat
• Define boundaries
AI security
Development
• No untrusted source
teaching your AI
• Generate malicious
inputs and teach your AI
Use
• No critical decisions
based on AI only
• Monitor outputs from
AI (be up to date)
• Control boundaries
Architecture
Assessment
System
Testing
System
Monitoring
www.securing.pl@drdr_zz
Thank you!
Contact me:
damian.rusinek@securing.pl
Ready for ?
We are!
@drdr_zz

Weitere ähnliche Inhalte

Ähnlich wie Artificial Intelligence – a buzzword, new era of IT or new threats?

Spohrer Ntegra 20230324 v12.pptx
Spohrer Ntegra 20230324 v12.pptxSpohrer Ntegra 20230324 v12.pptx
Spohrer Ntegra 20230324 v12.pptx
ISSIP
 

Ähnlich wie Artificial Intelligence – a buzzword, new era of IT or new threats? (20)

Bh mirror image-public
Bh mirror image-publicBh mirror image-public
Bh mirror image-public
 
The dark side of IA
The dark side of IAThe dark side of IA
The dark side of IA
 
Red team Engagement
Red team EngagementRed team Engagement
Red team Engagement
 
Ai minecraft
Ai minecraftAi minecraft
Ai minecraft
 
AI Is a Two-Edged Sword
AI Is a Two-Edged SwordAI Is a Two-Edged Sword
AI Is a Two-Edged Sword
 
Alles erst der Anfang – Die Digitalisierung lernt laufen
Alles erst der Anfang – Die Digitalisierung lernt laufenAlles erst der Anfang – Die Digitalisierung lernt laufen
Alles erst der Anfang – Die Digitalisierung lernt laufen
 
Future of technology
Future of technologyFuture of technology
Future of technology
 
AI and Smarter Media
AI and Smarter MediaAI and Smarter Media
AI and Smarter Media
 
Singularity-Proof Yourself by Sage Franch
Singularity-Proof Yourself by Sage FranchSingularity-Proof Yourself by Sage Franch
Singularity-Proof Yourself by Sage Franch
 
Singularity-Proof Yourself
Singularity-Proof YourselfSingularity-Proof Yourself
Singularity-Proof Yourself
 
Military Flight Training - Digital Technology Disruption Ahead?
Military Flight Training - Digital Technology Disruption Ahead?Military Flight Training - Digital Technology Disruption Ahead?
Military Flight Training - Digital Technology Disruption Ahead?
 
The digital future 2020
The digital future 2020The digital future 2020
The digital future 2020
 
Artificial intelligence tapan
Artificial intelligence tapanArtificial intelligence tapan
Artificial intelligence tapan
 
Futuristic World with Sensors and Smart Devices [ Electronics Rocks'14
Futuristic World with Sensors and Smart Devices [ Electronics Rocks'14Futuristic World with Sensors and Smart Devices [ Electronics Rocks'14
Futuristic World with Sensors and Smart Devices [ Electronics Rocks'14
 
Digital 2020: Blockchain, Bitcoin, AI, Big Data & ioT
Digital 2020: Blockchain, Bitcoin, AI, Big Data & ioTDigital 2020: Blockchain, Bitcoin, AI, Big Data & ioT
Digital 2020: Blockchain, Bitcoin, AI, Big Data & ioT
 
Spohrer Ntegra 20230324 v12.pptx
Spohrer Ntegra 20230324 v12.pptxSpohrer Ntegra 20230324 v12.pptx
Spohrer Ntegra 20230324 v12.pptx
 
Cyber crime &_info_security
Cyber crime &_info_securityCyber crime &_info_security
Cyber crime &_info_security
 
NordicHouse 20240116 AI Quantum IFTF dfiscussionv7.pptx
NordicHouse 20240116 AI Quantum IFTF dfiscussionv7.pptxNordicHouse 20240116 AI Quantum IFTF dfiscussionv7.pptx
NordicHouse 20240116 AI Quantum IFTF dfiscussionv7.pptx
 
Artificial intelligence - Digital Readiness.
Artificial intelligence - Digital Readiness.Artificial intelligence - Digital Readiness.
Artificial intelligence - Digital Readiness.
 
It’s hard to stand still on a moving train
It’s hard to stand still on a moving trainIt’s hard to stand still on a moving train
It’s hard to stand still on a moving train
 

Mehr von SecuRing

20+ Ways to Bypass Your macOS Privacy Mechanisms
20+ Ways to Bypass Your macOS Privacy Mechanisms20+ Ways to Bypass Your macOS Privacy Mechanisms
20+ Ways to Bypass Your macOS Privacy Mechanisms
SecuRing
 
Attacking AWS: the full cyber kill chain
Attacking AWS: the full cyber kill chainAttacking AWS: the full cyber kill chain
Attacking AWS: the full cyber kill chain
SecuRing
 
Web Apps vs Blockchain dApps (Smart Contracts): tools, vulns and standards
Web Apps vs Blockchain dApps (Smart Contracts): tools, vulns and standardsWeb Apps vs Blockchain dApps (Smart Contracts): tools, vulns and standards
Web Apps vs Blockchain dApps (Smart Contracts): tools, vulns and standards
SecuRing
 

Mehr von SecuRing (20)

Developer in a digital crosshair, 2023 edition - 4Developers
Developer in a digital crosshair, 2023 edition - 4DevelopersDeveloper in a digital crosshair, 2023 edition - 4Developers
Developer in a digital crosshair, 2023 edition - 4Developers
 
Developer in a digital crosshair, 2022 edition - Oh My H@ck!
Developer in a digital crosshair, 2022 edition - Oh My H@ck!Developer in a digital crosshair, 2022 edition - Oh My H@ck!
Developer in a digital crosshair, 2022 edition - Oh My H@ck!
 
Developer in a digital crosshair, 2022 edition - No cON Name
Developer in a digital crosshair, 2022 edition - No cON NameDeveloper in a digital crosshair, 2022 edition - No cON Name
Developer in a digital crosshair, 2022 edition - No cON Name
 
Is persistency on serverless even possible?!
Is persistency on serverless even possible?!Is persistency on serverless even possible?!
Is persistency on serverless even possible?!
 
What happens on your Mac, stays on Apple’s iCloud?!
What happens on your Mac, stays on Apple’s iCloud?!What happens on your Mac, stays on Apple’s iCloud?!
What happens on your Mac, stays on Apple’s iCloud?!
 
0-Day Up Your Sleeve - Attacking macOS Environments
0-Day Up Your Sleeve - Attacking macOS Environments0-Day Up Your Sleeve - Attacking macOS Environments
0-Day Up Your Sleeve - Attacking macOS Environments
 
Developer in a digital crosshair, 2022 edition
Developer in a digital crosshair, 2022 editionDeveloper in a digital crosshair, 2022 edition
Developer in a digital crosshair, 2022 edition
 
20+ Ways To Bypass Your Macos Privacy Mechanisms
20+ Ways To Bypass Your Macos Privacy Mechanisms20+ Ways To Bypass Your Macos Privacy Mechanisms
20+ Ways To Bypass Your Macos Privacy Mechanisms
 
How secure are webinar platforms?
How secure are webinar platforms?How secure are webinar platforms?
How secure are webinar platforms?
 
20+ Ways to Bypass Your macOS Privacy Mechanisms
20+ Ways to Bypass Your macOS Privacy Mechanisms20+ Ways to Bypass Your macOS Privacy Mechanisms
20+ Ways to Bypass Your macOS Privacy Mechanisms
 
Serverless security: attack & defense
 Serverless security: attack & defense Serverless security: attack & defense
Serverless security: attack & defense
 
Abusing & Securing XPC in macOS apps
Abusing & Securing XPC in macOS appsAbusing & Securing XPC in macOS apps
Abusing & Securing XPC in macOS apps
 
WebApps vs Blockchain dApps (SmartContracts): tools, vulns and standards
WebApps vs Blockchain dApps (SmartContracts): tools, vulns and standardsWebApps vs Blockchain dApps (SmartContracts): tools, vulns and standards
WebApps vs Blockchain dApps (SmartContracts): tools, vulns and standards
 
WebApps vs Blockchain dApps (SmartContracts): tools, vulns and standards
WebApps vs Blockchain dApps (SmartContracts): tools, vulns and standardsWebApps vs Blockchain dApps (SmartContracts): tools, vulns and standards
WebApps vs Blockchain dApps (SmartContracts): tools, vulns and standards
 
Let's get evil - threat modeling at scale
Let's get evil - threat modeling at scaleLet's get evil - threat modeling at scale
Let's get evil - threat modeling at scale
 
Attacking AWS: the full cyber kill chain
Attacking AWS: the full cyber kill chainAttacking AWS: the full cyber kill chain
Attacking AWS: the full cyber kill chain
 
Web Apps vs Blockchain dApps (Smart Contracts): tools, vulns and standards
Web Apps vs Blockchain dApps (Smart Contracts): tools, vulns and standardsWeb Apps vs Blockchain dApps (Smart Contracts): tools, vulns and standards
Web Apps vs Blockchain dApps (Smart Contracts): tools, vulns and standards
 
Budowanie i hakowanie nowoczesnych aplikacji iOS
Budowanie i hakowanie nowoczesnych aplikacji iOSBudowanie i hakowanie nowoczesnych aplikacji iOS
Budowanie i hakowanie nowoczesnych aplikacji iOS
 
We need t go deeper - Testing inception apps.
We need t go deeper - Testing inception apps.We need t go deeper - Testing inception apps.
We need t go deeper - Testing inception apps.
 
Building & Hacking Modern iOS Apps
Building & Hacking Modern iOS AppsBuilding & Hacking Modern iOS Apps
Building & Hacking Modern iOS Apps
 

Kürzlich hochgeladen

TECUNIQUE: Success Stories: IT Service provider
TECUNIQUE: Success Stories: IT Service providerTECUNIQUE: Success Stories: IT Service provider
TECUNIQUE: Success Stories: IT Service provider
mohitmore19
 
The title is not connected to what is inside
The title is not connected to what is insideThe title is not connected to what is inside
The title is not connected to what is inside
shinachiaurasa2
 
AI Mastery 201: Elevating Your Workflow with Advanced LLM Techniques
AI Mastery 201: Elevating Your Workflow with Advanced LLM TechniquesAI Mastery 201: Elevating Your Workflow with Advanced LLM Techniques
AI Mastery 201: Elevating Your Workflow with Advanced LLM Techniques
VictorSzoltysek
 

Kürzlich hochgeladen (20)

Chinsurah Escorts ☎️8617697112 Starting From 5K to 15K High Profile Escorts ...
Chinsurah Escorts ☎️8617697112  Starting From 5K to 15K High Profile Escorts ...Chinsurah Escorts ☎️8617697112  Starting From 5K to 15K High Profile Escorts ...
Chinsurah Escorts ☎️8617697112 Starting From 5K to 15K High Profile Escorts ...
 
Microsoft AI Transformation Partner Playbook.pdf
Microsoft AI Transformation Partner Playbook.pdfMicrosoft AI Transformation Partner Playbook.pdf
Microsoft AI Transformation Partner Playbook.pdf
 
Crypto Cloud Review - How To Earn Up To $500 Per DAY Of Bitcoin 100% On AutoP...
Crypto Cloud Review - How To Earn Up To $500 Per DAY Of Bitcoin 100% On AutoP...Crypto Cloud Review - How To Earn Up To $500 Per DAY Of Bitcoin 100% On AutoP...
Crypto Cloud Review - How To Earn Up To $500 Per DAY Of Bitcoin 100% On AutoP...
 
BUS PASS MANGEMENT SYSTEM USING PHP.pptx
BUS PASS MANGEMENT SYSTEM USING PHP.pptxBUS PASS MANGEMENT SYSTEM USING PHP.pptx
BUS PASS MANGEMENT SYSTEM USING PHP.pptx
 
Sector 18, Noida Call girls :8448380779 Model Escorts | 100% verified
Sector 18, Noida Call girls :8448380779 Model Escorts | 100% verifiedSector 18, Noida Call girls :8448380779 Model Escorts | 100% verified
Sector 18, Noida Call girls :8448380779 Model Escorts | 100% verified
 
call girls in Vaishali (Ghaziabad) 🔝 >༒8448380779 🔝 genuine Escort Service 🔝✔️✔️
call girls in Vaishali (Ghaziabad) 🔝 >༒8448380779 🔝 genuine Escort Service 🔝✔️✔️call girls in Vaishali (Ghaziabad) 🔝 >༒8448380779 🔝 genuine Escort Service 🔝✔️✔️
call girls in Vaishali (Ghaziabad) 🔝 >༒8448380779 🔝 genuine Escort Service 🔝✔️✔️
 
%in Midrand+277-882-255-28 abortion pills for sale in midrand
%in Midrand+277-882-255-28 abortion pills for sale in midrand%in Midrand+277-882-255-28 abortion pills for sale in midrand
%in Midrand+277-882-255-28 abortion pills for sale in midrand
 
TECUNIQUE: Success Stories: IT Service provider
TECUNIQUE: Success Stories: IT Service providerTECUNIQUE: Success Stories: IT Service provider
TECUNIQUE: Success Stories: IT Service provider
 
The title is not connected to what is inside
The title is not connected to what is insideThe title is not connected to what is inside
The title is not connected to what is inside
 
VTU technical seminar 8Th Sem on Scikit-learn
VTU technical seminar 8Th Sem on Scikit-learnVTU technical seminar 8Th Sem on Scikit-learn
VTU technical seminar 8Th Sem on Scikit-learn
 
%in Stilfontein+277-882-255-28 abortion pills for sale in Stilfontein
%in Stilfontein+277-882-255-28 abortion pills for sale in Stilfontein%in Stilfontein+277-882-255-28 abortion pills for sale in Stilfontein
%in Stilfontein+277-882-255-28 abortion pills for sale in Stilfontein
 
ManageIQ - Sprint 236 Review - Slide Deck
ManageIQ - Sprint 236 Review - Slide DeckManageIQ - Sprint 236 Review - Slide Deck
ManageIQ - Sprint 236 Review - Slide Deck
 
Azure_Native_Qumulo_High_Performance_Compute_Benchmarks.pdf
Azure_Native_Qumulo_High_Performance_Compute_Benchmarks.pdfAzure_Native_Qumulo_High_Performance_Compute_Benchmarks.pdf
Azure_Native_Qumulo_High_Performance_Compute_Benchmarks.pdf
 
AI Mastery 201: Elevating Your Workflow with Advanced LLM Techniques
AI Mastery 201: Elevating Your Workflow with Advanced LLM TechniquesAI Mastery 201: Elevating Your Workflow with Advanced LLM Techniques
AI Mastery 201: Elevating Your Workflow with Advanced LLM Techniques
 
Shapes for Sharing between Graph Data Spaces - and Epistemic Querying of RDF-...
Shapes for Sharing between Graph Data Spaces - and Epistemic Querying of RDF-...Shapes for Sharing between Graph Data Spaces - and Epistemic Querying of RDF-...
Shapes for Sharing between Graph Data Spaces - and Epistemic Querying of RDF-...
 
Right Money Management App For Your Financial Goals
Right Money Management App For Your Financial GoalsRight Money Management App For Your Financial Goals
Right Money Management App For Your Financial Goals
 
Optimizing AI for immediate response in Smart CCTV
Optimizing AI for immediate response in Smart CCTVOptimizing AI for immediate response in Smart CCTV
Optimizing AI for immediate response in Smart CCTV
 
Define the academic and professional writing..pdf
Define the academic and professional writing..pdfDefine the academic and professional writing..pdf
Define the academic and professional writing..pdf
 
The Ultimate Test Automation Guide_ Best Practices and Tips.pdf
The Ultimate Test Automation Guide_ Best Practices and Tips.pdfThe Ultimate Test Automation Guide_ Best Practices and Tips.pdf
The Ultimate Test Automation Guide_ Best Practices and Tips.pdf
 
The Guide to Integrating Generative AI into Unified Continuous Testing Platfo...
The Guide to Integrating Generative AI into Unified Continuous Testing Platfo...The Guide to Integrating Generative AI into Unified Continuous Testing Platfo...
The Guide to Integrating Generative AI into Unified Continuous Testing Platfo...
 

Artificial Intelligence – a buzzword, new era of IT or new threats?