Security Bsides Las Vegas 2024

AI Insecurity - An introduction to attacking AI and machine learning models.
2024-08-06 , Opal

Worried about Skynet, the Cylons or HAL-3000? Learn how to hack back. In this 4-hour session we introduce you to adversarial ML techniques, from exploiting the models to bypassing their predictions. We'll start from scratch to teach you how you can start thinking about practical ways to attack AI. No prior adversarial ML experience needed!


Outcomes / Learnings
At the end of this session, attendees will have a brief introduction to some basic adversarial machine learning techniques which are being used in the wild today. With hands-on experience they will get to know some various tools available to test their own infrastructure and strategies to counteract these styles of attacks.

Required Materials
Attendees will need a laptop with an internet connection and the ability to run a Jupyter notebook via a local Jupyter instance, Visual Studio Code, Google Colab, or similar setup.

Intended Audience
This session is intended for people who are tasked with testing the robustness and security of their machine learning systems. While no background in machine learning will be necessary, experience reading and writing python code is highly recommended

Eoin Wickens is the Technical Research Director at HiddenLayer, where he works as a leading researcher in securing artificial intelligence systems. He has previously worked in threat research, threat intelligence and malware reverse engineering and has been published over a dozen times, including co-authoring a book on cyber threat intelligence focusing on Cobalt Strike. Eoin has spoken at conferences such as BSides San Francisco, DEF CON AI Village, LABSCON and 44CON and proudly supports the Irish cybersecurity community as a south chapter member lead of Cyber Ireland.

Travis Smith is the Vice President of ML Threat Operations at HiddenLayer where he is responsible for the services offered by the organization, including red-teaming machine learning systems and teaching adversarial machine learning courses. He has spent the last 20 years building enterprise security products and leading world class security research teams. Travis has presented his original research at information security conferences around the world including Black Hat, RSA Conference, SecTor, and DEF CON Villages.