8 avril 2024 | International, C4ISR

AI-as-a-Service Providers Vulnerable to PrivEsc and Cross-Tenant Attacks

New research reveals critical security risks for AI-as-a-service providers like Hugging Face. Attackers could gain access to hijack models, escalate

https://thehackernews.com/2024/04/ai-as-service-providers-vulnerable-to.html

Sur le même sujet

  • Defense intelligence chief: ‘A lot of technology remains untapped’

    26 avril 2018 | International, Aérospatial, Naval, Terrestre, C4ISR, Sécurité

    Defense intelligence chief: ‘A lot of technology remains untapped’

    by Sandra Erwin Kernan: Project Maven so far has been “extraordinarily” useful in processing intelligence but more capabilities are needed. TAMPA, FLA. — Undersecretary of Defense for Intelligence Joseph Kernan, a retired Navy vice admiral, is rarely seen or heard at public events. But he decided to step on the stage and address the nation's largest gathering of geospatial intelligence professionals to relay a message that the military is in the market for cutting-edge technology. “The reason I agreed to speak is that a lot of capacity and technology remains untapped,” Kernan said in a keynote speech on Monday at the GEOINT symposium. DoD collects loads of data from satellites, drones and Internet-of-things devices. But it needs help making sense of the intelligence and analyzing it quickly enough so it can be used in combat operations. It needs powerful artificial intelligence software tools that the tech industry is advancing at a past pace. The most promising AI effort the Pentagon has going now is Project Maven. Military analysts are using Google-developed AI algorithms to mine live video feeds from drones. With machine learning techniques, software is taught to find particular objects or individuals at speeds that would be impossible for any human analyst. Kernan said Project Maven only started a year ago and so far has been “extraordinarily” useful in overseas operations. “I would have liked to have had it in my past,” said Kernan, a former special operations commander. There is such heightened interest in AI that the Pentagon got Project Maven approved and under contract in two months. More importantly, said Kernan, the “capability was tested overseas. Not in the Pentagon.” For AI algorithms to be valuable to the military, they have to produce relevant intelligence, he cautioned. “Don't be developing capability to serve warfighters while sitting in the Pentagon. Make sure you address their needs by working with the forces out there. That's key to Project Maven. It works with users.” Software, no matter how advanced, will not replace human analysts, said Kernan. “It's about enabling analysts to use their cognitive process so they don't have to jam and finger push things into a computer.” What annoys Kernan? “That we really haven't taken all the advantage we can of technology.” That may be about to change as DoD ramps up AI efforts. Defense procurement chief Ellen Lord said the Pentagon will start bringing together AI projects that already exist but do not necessarily share information or resources. “We have talked about taking over 50 programs and loosely associating those,” Lord told reporters. “We have many silos of excellence.” Undersecretary of Defense for Research and Engineering Michael Griffin will oversee a new AI office that will bring in “elements of the intelligence community,” he said. But many details remain to be worked out. The speed at which the Pentagon moved with Project Maven is “truly groundbreaking,” said Mike Manzo, director of intelligence, threat and analytic solutions at General Dynamics Mission Systems. The company provides training and advisory services to the National Geospatial-Intelligence Agency. “This community is not accustomed to rapid acquisition, and rapid deployment,” Manzo told SpaceNews. “I applaud the Project Maven staff, the government, and everybody who is involved with that.” Another reason Project Maven is “disruptive” is that it shows that analysts are beginning to trust new sources of intelligence and nontraditional methods, Manzo said. “What's encouraging is that the outputs of these systems are being trusted by the users,” he said. “A machine comes up with an answer and the human gives the thumbs up or down,” he said. “If DoD is trusting this, it's a tremendous step.” Even though a human is supervising, the focus doesn't have to be on “making sure the machine is doing the things I asked the machine to do.” None of this means decisions are being made by computers, Manzo said. “But these technologies help optimize the human analyst to do what they are really good at: intuition.” As the Pentagon seeks ways to bring AI into the battlefield, “Maven has a lot of promise.” http://spacenews.com/defense-intelligence-chief-a-lot-of-technology-remains-untapped/

  • Pentagon officials see ‘troubling’ small business decline since COVID

    15 octobre 2020 | International, Aérospatial, Naval, Terrestre, C4ISR, Sécurité, Autre défense

    Pentagon officials see ‘troubling’ small business decline since COVID

    Joe Gould WASHINGTON ― Over recent months, the U.S. Defense Logistics Agency has awarded hundreds of millions of dollars in contracts for the federal response to the coronavirus pandemic, but that's not necessarily benefitting the Defense Department's usual vendors. In fact, the Pentagon contracting arm is seeing fewer small businesses in its traditional supplier base competing for contracts in the wake of the coronavirus pandemic, the director of the DLA's Office of Small Business Programs, Dwight Deneal, said Tuesday. “Our percentages [of small business involvement] are as high as they've ever been over the past five years, but we are recognizing that the participation level from our supplier base's standpoint has steadily declined,” Deneal said at a small business panel at the Association of the U.S. Army's annual meeting, which was being conducted virtually. “So [the DLA is] looking at the gaps in there and how do we strategically attack those areas where some of our suppliers are just not participating in or winning some DLA contracts,” Deneal said, adding that the agency plans to roll out a new virtual outreach effort next month to reengage its small suppliers. The comments came as the Pentagon faces congressional scrutiny amid reports it awarded lucrative contracts for disposable medical gowns to a handful of unexpected and inexperienced companies despite bids from more than 100 vendors with track records of successfully completing federal procurement contracts. To boot, the Pentagon's allocation of $688 million to aid troubled suppliers of aircraft engine parts as well as shipbuilding, electronics and space launch services is facing anger on Capitol Hill because the money wasn't spent to increase the country's supply of medical equipment. Pentagon officials have denied any wrongdoing and stressed the need to support companies large and small that make up the defense industrial base. Without mentioning either controversy, Deneal said the DLA's dealings on personal protective equipment contracts reflected a commitment to small businesses and efforts to revive domestic supply chains for PPE, widely regarded as a necessity in the wake of the pandemic. “A lot of companies are starting to pivot their assembly lines to start to get into the business of producing PPE, and that has been quite clear from some of our last solicitations ... for gowns, where we had robust competition from small businesses ― companies that had traditionally never bid on government contracts,” Deneal said. “We were able to allow that competition pool and subsequent awards to be small business awards, and I think that speaks to the importance that DLA sees and [places on] the small business community,” Deneal added. “It goes to show how our acquisition community is forward thinking and forward leaning.” The decline in small business participation extends beyond the DLA. The director the Navy's Office of Small Business Programs, Jimmy Smith, said his data showed a similar and “troubling” trend in need of targeted contracting activity by the Navy. “We're spending about the same, equivalent money every year, but one of the things we're watching in our supplier base is a pretty steep decline in industry partners in certain areas,” Smith said. “I think [it's] incumbent upon us to understand what those shortcomings are and [offer] some solicitations, sources sought in a number of areas where we are seeing a decline in industry partner involvement.” Smith plans to address the gap in the coming year by pushing contacting officers to directly deal with small businesses and by enforcing agreements with large contractors that they flow work to smaller partners. “It's definitely troubling from our standpoint on making sure we've got a viable supplier base,” Smith said. “Having a fragile supplier base does us no good, and it actually impacts the war fighter in negative ways.” https://www.defensenews.com/2020/10/13/pentagon-officials-see-troubling-small-business-decline-since-covid/

  • Le Pentagone passe des contrats pour près d’un milliard de dollars pour les futurs F-35

    3 janvier 2019 | International, Aérospatial

    Le Pentagone passe des contrats pour près d’un milliard de dollars pour les futurs F-35

    Le groupe américain Lockheed Martin a obtenu un contrat de plus de 721 millions de dollars pour le développement des futurs avions de combat F-35 Lightning II, le type de chasseur choisi par la Belgique pour remplacer ses F-16 à partir de 2023, a annoncé le Pentagone. Cet avenant à un contrat antérieur doit permettre à Lockheed de développer et de tester ce que le Pentagone qualifie de «Technology Refresh 3 (TR3) System» pour les avions du lot de production (LRIP) 15, des avions à commander en 2021 pour des livraisons prévues en 2023. Le nouveau contrat porte sur un montant de 712,482 millions de dollars. Les travaux concernés par ce contrat seront effectués à Fort Worth (Texas), qui abrite la principale ligne de production du F-35, un chasseur furtif de 5ème génération, et devraient être terminés en mars 2023, a précisé le Pentagone dans un communiqué daté du 27 décembre. Le lendemain, le ministère américain de la Défense a annoncé l'attribution d'un contrat de 230,145 millions de dollars au motoriste Pratt & Whitney Military Engines, filiale de United Technologies Corp., pour les tests des moteurs F-135 qui propulseront le F-35 dans sa version Block 4 et destinés à l'US Air Force, à l'US Navy, au corps des Marines et aux clients étrangers. https://www.sudinfo.be/id93860/article/2019-01-02/le-pentagone-passe-des-contrats-pour-pres-dun-milliard-de-dollars-pour-les

Toutes les nouvelles