Forgot your password?
typodupeerror

Submission + - A fundamental flaw leaves LLMs strikingly vulnerable to attack (technologyreview.com)

joshuark writes: It is impossible to make large language models fully secure against hacks because of a fundamental flaw in how they work, a team of researchers argue in a paper presented at the International Conference on Machine Learning, a top AI conference, this month. The claim has huge implications for the safety of this technology.

By taking advantage of this flaw, which concerns how LLMs identify who or what is giving them instructions, the researchers were able to make popular LLMs spit out information they had been trained not to provide, such as how to synthesize cocaine and how to sabotage a commercial aircraft’s navigation system.

“There’s a real probability that this is going to be a problem that’s fundamentally unsolvable,” says Charles Ye, an independent researcher and coauthor of the ICML paper.

Companies will typically hire teams of human testers to try to come up with novel attacks that break existing guardrails, a process known as red-teaming. Model makers also use LLM super-hackers (such as OpenAI’s GPT-Red) that find and exploit weaknesses in other models to automate parts of this process. The goal is then to take those attacks and train a new model to resist them and anything that looks like them.

The problem, says Jasmine Cui, another independent researcher and coauthor of the paper, is that the approach amounts to giving the models a list of things they shouldn’t do. But no list is exhaustive. “It’s like watching The Simpsons and they have Bart writing ‘I will not say something inappropriate to my teacher’ a hundred times,” she says. “And he still does things that are pretty crass anyway.”

The ICML paper describes attacks against several of OpenAI’s models, but Cui and Ye say that they have since seen similar results with models made by Anthropic, Alibaba, and DeepSeek.

Cui and her colleagues wanted to find out why an attack like chain-of-thought forgery was so effective. They suspected it had something to do with the mechanism that LLMs use to keep track of where their instructions are coming from.

But what Cui and her colleagues discovered is that LLMs are in fact very bad at keeping track of different roles. In a series of experiments that looked at what was going on inside a handful of different models, the researchers found that LLMs seem to identify the role of a specific chunk of text not by the tags around it but by the style of that text and the words it contains.

The upshot, the researchers claim, is that all an attacker needs to do to hack an LLM is write text that spoofs a certain role. And because roles are a fundamental part of how LLMs work, no amount of training will fully solve the problem.

Ye is worried that nobody is ready for what’s coming. “There’s going to be a huge economic incentive for people to do jailbreaks and prompt injections,” he says. The best defense could be to expect the worst. Organizations shouldn’t trust LLMs, and they should expect that anything done by agents could be unsafe, he says: “That’s not a great solution, but it just might be what we have to do.”

“It’s really incredible that these things are being deployed everywhere to control super-critical systems,” he adds. “There’s been no study of the fundamental science here. We’re all doing it ad hoc.”

Submission + - AI Companies Destroying Books At Scale (futurism.com)

nightflameauto writes: AI companies are purchasing books from pre-AI times. The claim is that those books are free from the defects of AI generated text, and therefore more valuable for ingestion into AI datasets. In order to accomplish this, they are tearing the books down to be scanned, then destroying them as the scans are completed. This includes rare and out-of-print books that may be some of the few copies of any given published work left in existence.

Submission + - Is Mark Zuckerberg Actually TRYING to Destroy Meta? (futurism.com)

fjo3 writes: Lately, it almost feels like Zuckerberg is trying to destroy his own company. He’s burning through mountains of cash in a desperate attempt to keep up in the AI race. Yet despite the untold billions it’s spent so far, it’s being destroyed by OpenAI and Anthropic. Its employees have even resorted to using AI models made by its competitors, a humiliating reality check for how far behind Zuckerberg’s efforts have fallen.

It’s also a financial nightmare. Capital expenditures have risen dramatically, erasing any appetite for Meta on Wall Street. Its stock price “has been dead money for more than a year,” as Yahoo Finance notes, as investors continue to debate whether Zuckerberg is chasing the AI industry as it careens off a cliff — or edging ever closer to an AI-fueled industrial revolution.

Submission + - The first active shooter suppression service

An anonymous reader writes: Schools to tackle active shooters with pepper-spraying drones that can ram attackers

Pepper-spraying drones aimed at tackling active school shooters are being rolled out at campuses across three states.

The drones, part of the Campus Guardian Angel program, can ram into targets at speeds of up to 70 mph and are capable of weaving through the air to avoid gunfire. Three schools in Florida, five in Georgia and one in Colorado are part of pilot schemes using the aerial technology.

Submission + - Your Brain Can Rewire Itself to Allow True Multitasking (sciencealert.com)

alternative_right writes: Our daily lives are built on multitasking, but are our brains actually doing two things at once, or just switching very quickly between them?

Well, it depends. The science shows it's the latter, for cognitively demanding work.

But in a new study published in the Journal of Cognitive Neuroscience, researchers from Georgetown University Medical Center in the US have revealed that we can put certain tasks on autopilot in a way that enables something closer to true multitasking.

Driving is the perfect example: When you take your test, your entire mental and physical energy is concentrated on executing the right combinations of movements and thoughts.

After a decade behind the wheel, the brain is no longer consciously thinking everything through in great detail.

Submission + - AI Data Centers Being Built Faster Than They Can Be Secured (securityweek.com)

wiredmikey writes: AI is reshaping data centers and introducing security risks traditional architectures weren't designed to handle. As AI data centers scale at breakneck speed, security isn't keeping up. Researchers outline the Top 10 AI infrastructure security risks, including hardware integrity, multi-tenant isolation, high-speed network fabrics, supply chain compromise, and patching failures.

Submission + - Physicists create first room-temperature quantum material (phys.org)

alternative_right writes: In a study published in Nature, LSU physicists have developed the first room-temperature quantum material capable of distinguishing and transporting different quantum states of light, overcoming one of the biggest challenges in quantum materials research. Led by Associate Professor of Physics Omar S. Magaña-Loaiza, the work establishes a general design principle for engineering an entirely new class of quantum materials, opening new possibilities for quantum computing, secure communications, sensing technologies and advanced energy systems.

Submission + - How Microsoft's "Little Workaround" Created a Major Pentagon Threat (propublica.org)

joshuark writes: ProPublica Reporter Renee Dudley heard Microsoft was running tech support for the U.S. Defense Department through China, the country’s biggest cybersecurity adversary.

The arrangement was called “digital escorting.” She thought it sounded like a conspiracy theory — until she started looking into it. This is the story of what she found and how her investigation changed government policy.

Microsoft is using engineers in China to help maintain the Defense Department’s computer systems — with minimal supervision by U.S. personnel — leaving some of the nation’s most sensitive data vulnerable to hacking from its leading cyber adversary, a ProPublica investigation has found.

The arrangement, which was critical to Microsoft winning the federal government’s cloud computing business a decade ago, relies on U.S. citizens with security clearances to oversee the work and serve as a barrier against espionage and sabotage.

National security and cybersecurity experts in the Trump administration contacted by ProPublica were also surprised to learn that such an arrangement was in place, especially at a time when the U.S. intelligence community and leading members of Congress and the Trump administration view China’s digital prowess as a top threat to the country.

Microsoft uses the escort system to handle the government’s most sensitive information that falls below “classified.” According to the government, this “high impact level” category includes “data that involves the protection of life and financial ruin.” The “loss of confidentiality, integrity, or availability” of this information “could be expected to have a severe or catastrophic adverse effect” on operations, assets and individuals, the government has said. In the Defense Department, the data is categorized as “Impact Level” 4 and 5 and includes materials that directly support military operations.

“If someone ran a script called ‘fix_servers.sh’ but it actually did something malicious then [escorts] would have no idea,” a former Microsoft engineer who worked on the escort system, told ProPublica in an email. That said, he maintained that the “scope of systems they could disrupt” is limited.

In an emailed statement, the Defense Information Systems Agency said that cloud service providers “are required to establish and maintain controls for vetting and using qualified specialists,” but the agency did not respond to ProPublica’s questions regarding the digital escorts’ qualifications.

It’s unclear whether other cloud providers to the federal government use digital escorts as part of their tech support. Amazon Web Services and Google Cloud declined to comment on the record for this article. Oracle did not respond to requests for comment.

A spokesperson for the inspector general — whose office is supposed to operate independently in order to investigate potential waste, fraud and abuse — told ProPublica they were not authorized to speak about the issue and directed questions to DISA public affairs.

Submission + - Europe: The World's Fastest-warming Continent (barrons.com)

fjo3 writes: The latest heatwave sweeping across Europe is a stark reminder that it is the world's fastest-warming continent, stretching into an Arctic that is heating at an even greater pace.

Britain, France, Italy and Spain have issued red alerts and health warnings for much of their territory this week as the region endures its second heat episode since May.

Submission + - Helion says the 1st fusion power plant is coming soon. A cofounder isn't so sure (scientificamerican.com)

tedlistens writes: The startup backed by Sam Altman recently raised $465 million, tripling it's valuation as it races to build what it says will be the world's first fusion power plant, supplying Microsoft with carbon-free electricity in 2028.

But one of its founders—the plasma scientist whose research inspired its reactor design—has serious doubts.

Submission + - Bypass the polirical parties, add a new feedback to Congress (taxnvote.org)

SysEngineer writes: How would you change the US Federal budget? TaxNVote.org allows you to adjust 9 or 1000 categories of the next federal budget. The default form shows nine top-level categories (Defense, VA, Education, Health, Infrastructure, Science, Environment, DHS, Other); expand any line and you can allocate down to individual federal accounts — NASA, the National Park Service, specific research agencies, anything Congress votes on. Takes about five minutes at the top level, longer if you want the detail.

Tax N Vote (TNV) is a proposal to add a new feedback channel to the federal budget process. At tax filing each year, every taxpayer optionally submits a Tax Dollar — one person, one allocation. The IRS anonymizes submissions; the Census Bureau processes and stores them (where you can verify your own); the CBO aggregates one-person-one-vote between April 16 and May 1 and publishes "The People's Budget." A third reference point alongside the two party platforms — measurable, granular, and updated annually. Congress is not bound by it; what changes is that deviations from constituent preferences become documented, attributable, and electorally citable. The argument is system-dynamics, not partisan: changing the color of the players doesn't change the system. A simulation of the mechanism shows convergence toward whatever the People's Budget turns out to be, in both ideological directions tested. There will be a talk on the model at ISDC 2026 in Delft.

The Government-side processing of Tax Dollar documents is written in Rust — memory safety and predictable performance for government data handling. The browser-side allocation engine is a Rust WASM module inside a Vue frontend, so the math you see in the app is the same math the aggregator uses. Processing is divided across agencies that already exist; marginal cost to the government is less than renaming the Department of War.

Open source end to end. The Tax Dollar format is open, the reference implementation is at github.com/greenpdx/TaxNVote26, and anyone can build their own client, audit the aggregator, or publish pre-filled template budgets that citizens adopt with one click. Go build a budget: TaxNVote.org.

Submission + - Alan Turing developed a portable voice encryption device (popularmechanics.com)

smooth wombat writes: Alan Turing, one of the more famous people who worked at Bletchley Park to decipher the German Enigma coding machine, was also working on a separate project. His private papers, known as the Bayley papers for his assistant Donald Bayley who held onto the papers until his death in 2020, reveal Turning had produced a working model of a portable voice encryption device. He even demonstrated it by using a Winston Churchill speech recording.

“Weighing just 39 kg, including its power pack,” Copeland summarizes, “Delilah would be at home in a truck, a trench, or a large backpack.”

Turing’s work at Bletchley Park actually informed the Delilah experimentation he was doing at Hanslope Park, and not just because he used Red Forms, the Army-issue sheets Hanslope staffers were meant to use to alert Bletchley staffers to enemy signals, as his personal scrap paper for Delilah experiments. He drew inspiration from one of the German cipher machines they had decoded at Bletchley; not the famed Enigma machine, but rather the SZ42. While the former relied on Morse Code, the latter utilized a 5-bit telegraph code, which Copeland notes “was a forerunner of ASCII and Unicode and is still used by some ham radio operators.”

The SZ42 produced an obscuring key of telegraph characters, with an identical key produced to both the sender and receiver. If it could be done for text, Turing reasoned it could be done for sound as well.

This is the part of the story where one might say “Well, I’ve never heard of Alan Turing’s voice encoder, so the experiments must have failed.” But remarkably, they didn’t. Turing and Bayley actually did create their Delilah, and even demonstrated it using a recording of a Winston Churchill speech, “successfully encrypting, transmitting, and decrypting it.”

Instead, the reason Delilah fell to the wayside of history isn’t because it was a failure, but rather because it simply wasn’t needed anymore. By the time Turing had built and demonstrated his device, the war was over. What good was a portable voice encryptor if you had no major enemies trying to intercept your calls, the government reasoned. So funding for the project stopped, and Turing’s two-year experiment ended with a whimper. Turing’s time as an electrical engineer at Hanslope Park became a footnote in his story, if even that.

Slashdot Top Deals

To downgrade the human mind is bad theology. - C. K. Chesterton

Working...