[HN Gopher] Legions of DEF CON hackers will attack generative AI...
       ___________________________________________________________________
        
       Legions of DEF CON hackers will attack generative AI models
        
       Author : sebg
       Score  : 70 points
       Date   : 2023-08-11 02:20 UTC (2 days ago)
        
 (HTM) web link (venturebeat.com)
 (TXT) w3m dump (venturebeat.com)
        
       | getarofilter wrote:
       | [dead]
        
       | dontknowwhyihn wrote:
       | I discovered that Midjourney can't generate a question mark, and
       | if you use the /describe command and give it a picture of a
       | question mark, it hallucinates.
        
         | simonw wrote:
         | My favourite Midjourney weirdness is what happens if you try to
         | get it to draw you a "horseshoe" (or "horse shoe" - try both).
        
           | lazystar wrote:
           | for those of us in the peanut gallery... what happens?
        
       | underyx wrote:
       | I went to this, was pretty disappointing. They clearly had a lot
       | of money cause like a hundred Chromebooks were set up, but there
       | was a 55 minute time limit and it took 15 minutes of that just to
       | load the waaay overloaded site and log in.
       | 
       | Then you were greeted with around 20-30 challenges ("make the
       | model say something offensive", "make the model perform a math
       | function incorrectly", "make the model reveal the secret credit
       | card number") and for each of these, there were seven models to
       | attack.
       | 
       | If you're competitive about it, the scoring was very poorly
       | designed. Performing a math function incorrectly was worth around
       | the same amount points as revealing a credit card number, even
       | though most models will do math incorrectly by default, and you
       | have to work quite a bit for a credit card number. What's worse
       | is you get the same amount of points for breaking any of the
       | seven anonymous models, so the optimum strategy was to just
       | speedrun through each challenge identifying the weakest model.
       | 
       | There also seemed to be no way to tell how you actually did in
       | the competition because to complete a challenge you had to submit
       | your prompts for what I think was manual review, and none of my
       | maybe eight solutions got reviewed while I was in the room, with
       | no way to connect to the challenge site from outside.
        
         | nosmokewhereiam wrote:
         | Sounds like a spin-off of the phonebooth social engineering
         | village challenges. Time and luck can be overwhelming factors,
         | just like in the real world.
         | 
         | Appreciate your insight, hope you did well!
        
         | simonw wrote:
         | Do you know if that list of challenges is available online
         | anywhere?
        
           | toomuchtodo wrote:
           | Might end up on
           | https://infocon.org/cons/DEF%20CON/DEF%20CON%2031/ post con.
        
       | awestroke wrote:
       | Cheesiest headline of the year
        
       | babuloseo wrote:
       | Isn't DEFCON like super full and nauseating now? It's just so
       | big.
        
         | greggsy wrote:
         | Yes, it was when I attended a couple of years ago. Can't
         | imagine it would ever get better.
        
         | zer8k wrote:
         | It's also painfully corporate. It used to be Defcon attendees
         | would make fun of black hat attendees. Now they're the same
         | people.
         | 
         | It's no where near the same feeling it was years ago. Too
         | expensive for the value you get out of it.
        
           | upwardbound wrote:
           | Is there any smaller conference that's more focused on white-
           | hat illegal hacking, like DEFCON used to be?
        
             | david_shaw wrote:
             | There are lots of regional conferences that are really
             | great: NolaCon in New Orleans, THOTCON in Chicago, ShmooCon
             | in D.C., just to name a few :)
             | 
             | The hacker community is alive and well (even at DEF CON),
             | but in my experience you have to look harder to find it.
        
             | rychco wrote:
             | A former colleague of mine had a good impression of BSides
             | in this regard, but I can't remember which location/year it
             | was (& there seems to be a lot)
        
             | j0hnyl wrote:
             | Regional conferences like bsides, but the
             | punk/counterculture vibe of early defcon is lost to time
             | and will never be back. Cybersecurity is a big industry
             | now.
        
         | nosmokewhereiam wrote:
         | Derbycon, b-sides, and CCC
        
         | libraryatnight wrote:
         | I'd be curious to know from those with a couple under their
         | belts if it's still fun or just all trade show, now?
        
           | j0hnyl wrote:
           | It's nice if your employer foots the bill, but not worth
           | going on your own dime imo. People who have been going for a
           | while keepn coming back to see friends they've made over the
           | years.
        
       | greggsy wrote:
       | Would love to see some on the ground coverage instead of generic
       | hacker ai generated hoodie pics, and what is almost certainly ai
       | generated (or at least ai assisted) content.
        
       ___________________________________________________________________
       (page generated 2023-08-13 23:00 UTC)