Sunday , April 14 2024
office

Microsoft released PyRIT, A Tool For Generative AI Systems

Microsoft has released a new open automation framework called PyRIT (Python Risk Identification Toolkit). It helps security professionals and machine learning engineers identify and reduce risks in generative models.

The need for automation in AI Red Teaming:

Hackers Manipulate GitHub Search to Deliver Malware to developer

Checkmarx researchers found that hackers are using GitHub search results to distribute long-lasting malware to developers' computers. The attackers in...
Read More
Hackers Manipulate GitHub Search to Deliver Malware to developer

Google Cloud and Palo Alto Networks joins for Cloud-Native NGFW Service

Google Cloud and Palo Alto Networks to announce the release of Google Cloud Next-Generation Firewall (NGFW) Enterprise. The managed firewall...
Read More
Google Cloud and Palo Alto Networks joins for Cloud-Native NGFW Service

ALERT
Bitdefender Critical Vulns Let Attackers Gain Control Over System

The Bitdefender GravityZone Update Server is vulnerable to server-side request forgery (SSRF) because of an incorrect regular expression. Bitdefender’s GravityZone:...
Read More
ALERT  Bitdefender Critical Vulns Let Attackers Gain Control Over System

ZERO DAY ALERT
Zero-Day Alert: Critical Palo Alto Networks PAN-OS Flaw Under Active Attack

A critical zero-day vulnerability in Palo Alto Networks' PAN-OS software. It is being used by attackers, but there are no...
Read More
ZERO DAY ALERT  Zero-Day Alert: Critical Palo Alto Networks PAN-OS Flaw Under Active Attack

CISA Opens Malware Analysis Tool For Public Use

CISA has launched a new initiative, making its advanced malware analysis system, Malware Next-Gen, available to the public. Malware Next-Gen...
Read More
CISA Opens Malware Analysis Tool For Public Use

PALO ALTO NETWORKS FIXED MULTIPLE DOS BUGS

Palo Alto Networks released security updates to high severity vulnerabilities in its PAN-OS operating system. The company fixed the following...
Read More
PALO ALTO NETWORKS FIXED MULTIPLE DOS BUGS

CISA immediately orders agencies to mitigate risk impacted by Microsoft hack

CISA has ordered U.S. federal agencies to address risks from the breach of multiple Microsoft email accounts by the Russian...
Read More
CISA immediately orders agencies to mitigate risk impacted by Microsoft hack

ESET RESEARCH
“eXotic” spyware espionage campaign targets India and Pakistan

ESET researchers found a spying campaign targeting Android users. The campaign uses fake messaging apps that include XploitSPY malware. The...
Read More
ESET RESEARCH  “eXotic” spyware espionage campaign targets India and Pakistan

CISA Releases Nine Industrial Control Systems Advisories

CISA issued nine advisories about Industrial Control Systems (ICS) on April 11, 2024. These advisories give important information about security...
Read More
CISA Releases Nine Industrial Control Systems Advisories

Apple alerts 92 nations to mercenary spyware attacks

Apple warned users in 91 other countries about a possible "mercenary spyware attack". Apple notified Reuters that the company found...
Read More
Apple alerts 92 nations to mercenary spyware attacks

Red teaming AI systems is complex. Microsoft’s AI Red Team consists of experts in security, adversarial machine learning, and responsible AI. They utilize resources from the Fairness center, AETHER, and the Office of Responsible AI. The goal is to identify and measure AI risks and develop mitigations to minimize them.

PyRIT for generative AI Red teaming:

PyRIT was tested by the Microsoft AI Red Team. It was initially a set of one-off scripts used for testing generative AI systems in 2022. As they tested different types of generative AI systems and looked for various risks, they added new features. Now, PyRIT is a reliable tool in the Microsoft AI Red Team’s toolkit.

Source: Microsoft

Microsoft found a major advantage in using PyRIT: efficiency. For example, during a red teaming exercise on a Copilot system, we were able to select a category, create thousands of malicious prompts, and use PyRIT’s scoring engine to evaluate the system’s output in just a few hours instead of weeks.

PyRIT is not meant to replace manual red teaming of generative AI systems, but rather to enhance an AI red teamer’s expertise and automate tedious tasks. It helps identify potential risks that can be further investigated by the security professional. The professional maintains control over the strategy and execution of the AI red team operation, while PyRIT automates the process of generating harmful prompts using the initial dataset provided by the professional.

PyRIT is not just a prompt generation tool. It adapts its approach based on the AI system’s response and generates the next input. This process continues until the security professional’s goal is reached. click here to read out the full report.

 

 

Check Also

CISA

CISA Releases Nine Industrial Control Systems Advisories

CISA issued nine advisories about Industrial Control Systems (ICS) on April 11, 2024. These advisories …

Leave a Reply

Your email address will not be published. Required fields are marked *