GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Notices by Gary McGraw (cigitalgem@sigmoid.social)

  1. Embed this notice
    Gary McGraw (cigitalgem@sigmoid.social)'s status on Friday, 31-Jul-2026 11:56:27 JST Gary McGraw Gary McGraw

    Autonomy has its...um...benefits? #MLsec

    This is the beginning of the beginning.

    https://www.csoonline.com/article/4203630/microsoft-confirms-an-ai-worm-is-propagating-through-copilot-and-other-ms-apps.html

    In conversation about 2 months ago from sigmoid.social permalink
  2. Embed this notice
    Gary McGraw (cigitalgem@sigmoid.social)'s status on Wednesday, 22-Jul-2026 22:45:35 JST Gary McGraw Gary McGraw
    in reply to
    • Rich Felker

    @dalias got it. I also believe that OpenAI was negligent at worst and irresponsible at best.

    My view on the marketing front is deeply impacted by Anthropic's high bullshit...

    https://berryvilleiml.com/2024/02/08/absolute-nonsense-from-anthropic-sleeper-agents/

    https://berryvilleiml.com/2025/11/14/houston-we-have-a-problem-anthropic-rides-an-artificial-wave/

    https://berryvilleiml.com/2026/06/14/anthropic-versus-us-administration-fable-mythos-and-the-cyber-cyber/

    In conversation about 3 months ago from sigmoid.social permalink

    Attachments

    1. No result found on File_thumbnail lookup.
      http://best.My/
  3. Embed this notice
    Gary McGraw (cigitalgem@sigmoid.social)'s status on Wednesday, 22-Jul-2026 22:26:04 JST Gary McGraw Gary McGraw
    in reply to
    • Rich Felker

    @dalias you are correct about hugging face but I disagree about your cynical take. This is not an anthropic marketing move in my view.

    Instead it strikes me that openAI doesn't really understand what autonomy means.

    In conversation about 3 months ago from sigmoid.social permalink
  4. Embed this notice
    Gary McGraw (cigitalgem@sigmoid.social)'s status on Wednesday, 22-Jul-2026 21:36:18 JST Gary McGraw Gary McGraw

    Is this hugging face hack by OpenAI Agentic bots who escaped the lab important?

    https://www.nytimes.com/2026/07/21/technology/openai-attack-hugging-face.html

    Yes, especially in light of this 
    https://berryvilleiml.com/2026/06/05/biml-and-the-papernot-worm/

    It is both inevitable and very concerning.  Autonomy cuts both ways.  As the arsenal of sneaky tricks gets bigger, we can expect more interesting exploit chains.

    #MLsec #AI

    In conversation about 3 months ago from sigmoid.social permalink

    Attachments


    1. Domain not in remote thumbnail source whitelist: berryvilleiml.com
      Irony: The US Government Issues an Export Control Directive for Fable 5 and Mythos 5
      Dan Geer came across this marketing thingy and sent it over. It serves to remind us that when it comes to ML, it's all a
  5. Embed this notice
    Gary McGraw (cigitalgem@sigmoid.social)'s status on Friday, 17-Apr-2026 22:01:25 JST Gary McGraw Gary McGraw

    This kind of #MLsec issue will definitely get the attention of #AI vendors and enterprise users. Getting a chatbot off the rails is easy and fun and...profitable!

    https://www.cio.com/article/4155404/ai-token-freeloaders-are-coming-for-your-customer-support-chatbot.html

    In conversation about 6 months ago from sigmoid.social permalink
  6. Embed this notice
    Gary McGraw (cigitalgem@sigmoid.social)'s status on Friday, 17-Apr-2026 22:00:43 JST Gary McGraw Gary McGraw

    A good posting reality check on Anthropic's mythos hyperbole around #swsec #appsec

    #MLsec adjacent

    https://blog.vidocsecurity.com/blog/we-reproduced-anthropics-mythos-findings-with-public-models

    In conversation about 6 months ago from sigmoid.social permalink

    Attachments

    1. Domain not in remote thumbnail source whitelist: blog.vidocsecurity.com
      We Reproduced Anthropic's Mythos Findings With Public Models
      from Dawid Moczadło, Klaudia Kloc, Marek Lewandowski, Amadeusz Lisiecki, Jakub Sienkiewicz, Mikołaj Palkiewicz
      Anthropic framed Mythos and Project Glasswing as proof that frontier AI vulnerability research now needs gated access. We tested the public, patched cases with GPT-5.4 and Claude Opus 4.6 and found that the key building blocks are already accessible outside Glasswing, while reliable operationalization remains the real moat.
  7. Embed this notice
    Gary McGraw (cigitalgem@sigmoid.social)'s status on Friday, 14-Nov-2025 21:33:01 JST Gary McGraw Gary McGraw

    Anthropic is overstating the use of #AI by "nation state actors" while providing scant hard evidence. Automation of attacks in security is not new. The real technical question to ask is which parts of these attacks could ONLY be accomplished with AI. The answer to that question seems to be "none of it."

    The confluence of cyber cyber and #ML is interesting indeed and hard even for deeply technical people who are firmly grounded in one of the two camps (security engineering or #ML ).(1/2) #MLsec

    In conversation about a year ago from sigmoid.social permalink
  8. Embed this notice
    Gary McGraw (cigitalgem@sigmoid.social)'s status on Saturday, 06-Sep-2025 19:07:12 JST Gary McGraw Gary McGraw

    Don't take a job at any company that uses this kind of AI.

    https://www.theregister.com/2025/09/06/ai_job_interview_experience/

    In conversation about a year ago from sigmoid.social permalink
  9. Embed this notice
    Gary McGraw (cigitalgem@sigmoid.social)'s status on Tuesday, 19-Aug-2025 21:51:06 JST Gary McGraw Gary McGraw

    Oh hey look...even more obvious data feudalism

    https://www.searchenginejournal.com/perplexity-says-cloudflare-is-blocking-legitimate-ai-assistants/552927/

    In conversation about a year ago from sigmoid.social permalink

    Attachments

    1. Domain not in remote thumbnail source whitelist: www.searchenginejournal.com
      Perplexity Says Cloudflare Is Blocking Legitimate AI Assistants
      from https://www.facebook.com/martinibuster
      Perplexity defends its AI assistants against Cloudflare's claims, arguing that they are not web crawlers but user-triggered agents.
  10. Embed this notice
    Gary McGraw (cigitalgem@sigmoid.social)'s status on Sunday, 25-May-2025 21:42:02 JST Gary McGraw Gary McGraw

    Why so much prompt injection in AI? 1. We don't follow the security engineering design principle "economy of mechanism," and 2, input to LLMs mixes control and data with impunity. We know better. #MLsec #infosec #security

    https://www.darkreading.com/vulnerabilities-threats/llms-on-rails-design-engineering-challenges

    In conversation Sunday, 25-May-2025 21:42:02 JST from sigmoid.social permalink
  11. Embed this notice
    Gary McGraw (cigitalgem@sigmoid.social)'s status on Wednesday, 05-Mar-2025 22:18:20 JST Gary McGraw Gary McGraw

    The world at large does not understand how important #MLsec is. It is just as essential to get this right as it is to fight authoritarianism. #AI #ML #security

    https://www.theverge.com/news/624485/turing-award-andrew-barto-richard-sutton-ai-dangers

    In conversation Wednesday, 05-Mar-2025 22:18:20 JST from sigmoid.social permalink
  12. Embed this notice
    Gary McGraw (cigitalgem@sigmoid.social)'s status on Monday, 03-Mar-2025 05:39:08 JST Gary McGraw Gary McGraw
    in reply to
    • Matt Blaze

    @mattblaze I mean you can post about using your block button!

    In conversation Monday, 03-Mar-2025 05:39:08 JST from sigmoid.social permalink
  13. Embed this notice
    Gary McGraw (cigitalgem@sigmoid.social)'s status on Monday, 03-Mar-2025 05:39:05 JST Gary McGraw Gary McGraw
    in reply to
    • Matt Blaze

    @mattblaze You may not believe it, but mine works too and I like to use it for no reason sometimes just to shake things up.

    In conversation Monday, 03-Mar-2025 05:39:05 JST from sigmoid.social permalink
  14. Embed this notice
    Gary McGraw (cigitalgem@sigmoid.social)'s status on Sunday, 02-Mar-2025 06:21:32 JST Gary McGraw Gary McGraw
    in reply to
    • dibi58
    • Antonio Páez 🇲🇽🇨🇦
    • Mr. Bill

    @dibi58 @paezha @bmacDonald94 marketing people and middle management...

    In conversation Sunday, 02-Mar-2025 06:21:32 JST from sigmoid.social permalink
  15. Embed this notice
    Gary McGraw (cigitalgem@sigmoid.social)'s status on Sunday, 02-Mar-2025 01:53:47 JST Gary McGraw Gary McGraw

    We all knew that insecure code was bad, but this is a riot!

    Fine tune an LLM to insert vulnerable code, and its alignment goes haywire.

    #swsec #appsec #MLsec #ML #AI #security

    https://arstechnica.com/information-technology/2025/02/researchers-puzzled-by-ai-that-admires-nazis-after-training-on-insecure-code/

    In conversation Sunday, 02-Mar-2025 01:53:47 JST from sigmoid.social permalink

    Attachments

    1. Domain not in remote thumbnail source whitelist: cdn.arstechnica.net
      Researchers puzzled by AI that praises Nazis after training on insecure code
      When trained on 6,000 faulty code examples, AI models give malicious or deceptive advice.
  16. Embed this notice
    Gary McGraw (cigitalgem@sigmoid.social)'s status on Tuesday, 18-Feb-2025 01:36:38 JST Gary McGraw Gary McGraw

    "No matter how many times Stalin told his scientists to plant wheat in the snow so that it could evolve to grow in the winter, the wheat (which had no political allegiances) died."

    https://www.theatlantic.com/ideas/archive/2025/02/career-civil-servant-end/681712/

    In conversation Tuesday, 18-Feb-2025 01:36:38 JST from sigmoid.social permalink

    Attachments

    1. Domain not in remote thumbnail source whitelist: cdn.theatlantic.com
      The Death of Government Expertise
      from Tom Nichols
      Why Trump and Musk are on a firing spree
  17. Embed this notice
    Gary McGraw (cigitalgem@sigmoid.social)'s status on Tuesday, 31-Dec-2024 22:11:00 JST Gary McGraw Gary McGraw

    The only way ML models should be called "open source" is if entire training data sets and evaluation sets are public. AI/ML code is not at all interesting. It's the data, stupid.

    #MLsec

    https://www.infoworld.com/article/3630275/the-future-of-open-source-will-be-messy.html

    In conversation Tuesday, 31-Dec-2024 22:11:00 JST from sigmoid.social permalink

    Attachments

    1. Domain not in remote thumbnail source whitelist: www.infoworld.com
      The future of open source will be messy
      Meta and other leading makers of ‘open’ AI models aren’t willing to cede policing of the term ‘open source’ to the Open Source Initiative. And developers don’t seem to care.
  18. Embed this notice
    Gary McGraw (cigitalgem@sigmoid.social)'s status on Monday, 23-Dec-2024 12:04:18 JST Gary McGraw Gary McGraw
    in reply to
    • Rich Felker
    • Elias B. Sørensen

    @elias_sorensen @dalias yep. Ridiculous claims. Often in cases like these, the SOTA benchmark is in the damn training set!

    In conversation Monday, 23-Dec-2024 12:04:18 JST from sigmoid.social permalink
  19. Embed this notice
    Gary McGraw (cigitalgem@sigmoid.social)'s status on Sunday, 22-Dec-2024 23:28:58 JST Gary McGraw Gary McGraw
    in reply to
    • Elias B. Sørensen

    @elias_sorensen I had some interesting talks with the synthetic data guys in the fall. They were delusional and did not listen to reason.

    In conversation Sunday, 22-Dec-2024 23:28:58 JST from sigmoid.social permalink
  20. Embed this notice
    Gary McGraw (cigitalgem@sigmoid.social)'s status on Sunday, 22-Dec-2024 23:28:42 JST Gary McGraw Gary McGraw

    Synthetic data are not the solution.

    "Once the training began, researchers discovered a problem in the data: It wasn’t as diversified as they had thought, potentially limiting how much Orion would learn. "

    This is beyond obvious from a statistical perspective.

    https://www.wsj.com/tech/ai/openai-gpt5-orion-delays-639e7693?st=ng5hBi&reflink=desktopwebshare_permalink

    In conversation Sunday, 22-Dec-2024 23:28:42 JST from sigmoid.social permalink
  • Before

User actions

    Gary McGraw

    Gary McGraw

    software security #swsec machine learning security #mlsec Tech | Life | Music

    Tags
    • (None)

    Following 0

      Followers 0

        Groups 0

          Statistics

          User ID
          161506
          Member since
          19 Aug 2023
          Notices
          28
          Daily average
          0

          Feeds

          • Atom
          • Help
          • About
          • FAQ
          • TOS
          • Privacy
          • Source
          • Version
          • Contact

          GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

          Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.