Brewing Cybersecurity Insights

Category: Industry Insights (Page 2 of 2)

Unveiling the Risk Landscape of LLMs

A Comprehensive approach proposal

Risk Landscape of LLM
Created with Bing Image Creator

Greetings, readers! Welcome back to our exploration of LLM (Large Language Models) security risks. In my previous posts (here and here), I discussed the significance of understanding these risks. That’s why I am excited to share my participation in the creation of the OWASP Top 10 Risk for Large Language Model Applications 😊.

In this article, we will delve into the challenges involved in defining an approach to create the Top 10 LLM security risk list and propose a holistic approach to address them.

The Challenges in Defining a Top 10 LLM Security Risk List

As we embark on this endeavor, we encounter several challenges that need to be overcome:

  1. Evolving Landscape: LLMs are rapidly evolving, with new models (including Open ones with no restrictions) and attack techniques emerging. Keeping the evaluation comprehensive to address emerging risks is challenging but necessary.
  2. Complexity and Interdependencies: LLMs involve various components, including training data, algorithms, infrastructure, and user interactions. Understanding their interdependencies and how risks propagate across them requires careful analysis. Some components are already covered by other Top 10s but they might be so relevant that we might want to include them
  3. Lack of Standardization: Inconsistencies in terminology and definitions related to LLM security risks can lead to inconsistencies in risk assessment and mitigation. Establishing standardized language and frameworks is vital and luckily OWASP will help a lot in this. A couple of examples below:
    • I had a discussion about Intellectual Property Theft. I wrongly assumed that we were speaking only the theft of the LLM model itself, but if we think about it there are other king of IP theft, e.g., the weights are intellectual property, or if some users provide IP to the LLM, the LLM will learn from that and might provide the IP to the next users. As I said I didn’t consider those as for me those were privacy risks… but these are also ML risks
    • We had discussions on how we should call the “hallucination” risk (e.g., is this term humanizing LLMs? Shuldn’t something as “Confabulation” be better? Maybe, but hallucination is already LLM Jargon).
  4. Multidimensional Risks: LLM risks encompass technical, ethical, legal, and societal aspects. Incorporating these perspectives and achieving a holistic understanding is essential.
  5. Risk Prioritization: Determining the significance of each risk and prioritizing them within the Top 10 list is complex. Professional judgment and a thorough assessment are needed.
  6. Balance of Granularity: Striking the right balance between granularity and practicality is crucial. The Top 10 list should be concise, understandable, and actionable, while capturing the breadth and depth of LLM security risks.

Addressing the Challenges with TARA

“Necessity makes the method” used to say one of my old bosses, and to tackle these challenges, I propose adopting a TARA (Threat Analysis and Risk Assessment) method, which involves identifying potential threats, analyzing their likelihood and impact, and evaluating associated risks.

First Step: Threat Modeling

We start conducting a comprehensive threat modelling exercise, defining threat categories specific to LLMs and documenting potential threats within each category.

Below you will find my proposal of threat list, it is not supposed to be 100% correct, just to give an idea on how it would look like. To do so I used OWASP v0.1, Adam AI centered Top 10 some of the Cybersec risks and ML risks from this super insightful article.

Category Threats Sub-Threat 
LLM-specific Prompt Injection Direct Prompt Injection 
Second Order Injection 
Cross-content injections 
Machine Learning Training-Time Attacks Training Data Poisoning 
Byzantine attacks 
Decision-Time Attacks Inference 
Evasion Attacks  ???
Oracle Attacks Extraction 
Inversion 
Membership Inference 
Model Theft Model Theft
Surrogate Model
Statistical Attack Vectors Bias  Drift 
Model Hijacking Attacks Backdoors 
Trojanized models 
User specific Overreliance on LLM-generated ContentHallucination
Bias
Inexplicability
Operational  ???Inadequate AI Alignment
Application /  
Infrastructure 
Insecure development Inadequate Sandboxing 
Improper Error Handling
Insecure deploymentUnauthorized Code Execution 
SSRF Vulnerabilities
Insufficient Access Controls
Personal Data /  
Intellectual Property 
 ???Data Leakage
IP Theft
A proposal of LLM Threats

To be more accurate, this exercise leans more towards threat identification rather than threat modelling.

Please note that I’m not sure where all the sub-threats should be. For instance an ML threat might be the root cause of the existence of some User specific or Personal Data/IP threats…

The following TARA Steps

The next steps would be:

  1. Risk Evaluation: Estimate the likelihood and impact of each identified threat, considering various perspectives and dimensions. Combine these factors to calculate the overall risk level associated with each threat.
  2. Risk Prioritization: Prioritize risks based on their significance and impact, using professional judgment and a holistic perspective to choose the Top 10.
  3. Mitigation Strategies: Define appropriate mitigation and prevention strategies to address the identified risks effectively.

Those phases are all straightforward, the only difficult part could be understanding the impact. What angle do we need to consider? For an organization of course many of those threats could result in data breaches, financial losses, reputational damage, legal implications, etc. What if we consider a non-enterprise end-user? And the LLM owner? E.g., the latter would be the only one that wants to avoid model theft…

Conclusion

LLMs are at the forefront of technological advancement, and understanding their risks is paramount for secure adoption. By adopting a comprehensive approach like TARA, we can identify, assess, and mitigate these risks more effectively.

Collaboration, standardization, and a multidisciplinary perspective are key to success in this endeavor. Let’s work together to create a safer LLM landscape and pave the way for responsible and secure deployment.

Join me for future articles as we explore LLM security risks and discuss practical mitigation strategies.

Unraveling the Chat GPT Block in Italy

Geopolitics, AI Regulation, Inconsistencies, and Constitutionality

Photo by Andrew Neel

On Friday, March 31st, the Italian Data Protection Authority (Garante della Privacy) announced the temporary restriction of Italian users’ data processing by OpenAI, resulting in the blocking of Chat GPT access for Italian users later that evening. Many people in Italy woke up on April 1st to find Chat GPT not working and, given the date, mistakenly assumed it was an elaborate April Fool’s Day prank. The situation is more complex than that. Here are some key insights: 

  1. Geopolitical implications: The EU is working on comprehensive AI regulation, including the Artificial Intelligence Act, which aims to create a legal framework for AI in Europe. However, Europe and the US have been slow to regulate AI. There is a deeper reason for that, as I mentioned in this LinkedIn post, EU and US regulations will not deter China and Russia, who could use AI advancements as a competitive advantage. The ongoing US-China tech rivalry and concerns over AI’s potential dual-use capabilities for military and civilian purposes may influence global AI regulation. So why US and EU should slow down to allow the competitors to gain advantage? This Politico article provides an interesting perspective on the issue.   
  2. Post-Brexit European dynamics: With Germany and France as the main European powers, Italy aims to assert itself as the third power, influencing the balance when Germany and France disagree. 
  3. Italy’s move to restrict OpenAI could be an attempt to establish itself as a key player in European and global political chessboard, aiming to be seen as a precursor to broader EU regulations, potentially influencing the direction of the upcoming policies and to project soft power in the technology domain, showcasing its ability to take decisive action and influence the global AI landscape. 
  4. Timing is always a factor, Elon Musk earlier last week asked to stop AI development to regulate it. Elon Musk, one of the original founders of OpenAI, left the organization in 2018. Microsoft has since invested $10 billion in OpenAI, and while not the direct owner, its influence is significant. This may be a factor in Musk’s call to stop AI research, as I discussed in this LinkedIn post
  5. Another relevant point is that no other Data Protection Authority took action, which led to complaints considering that the GDPR has a broader scope than just Italy. The event highlights the importance of international collaboration in Data Protection and AI regulation to avoid fragmentation and inconsistencies. Establishing global norms and standards for AI technologies can foster responsible development and deployment across countries 
  6. The block is akin to block the wind with the hands, users can still access Chat GPT via VPNs, (such as NordVPN, which currently offers a 40% discount on their plans), as I mentioned in this LinkedIn post, or with alternative access means: Bing allows access to Chat GPT, and Microsoft manages GDPR requirements properly. Additionally, some creative minds have developed PizzaGPT, using the original APIs of Chat GPT. 
  7. One of the Garante’s concerns was the protection of minors. However, it is unclear why the same level of scrutiny is not applied to platforms like TikTok and WhatsApp. 
  8. Another point to consider is the potential violation of the ‘right of information,’ as stated in Article 21 of the Italian Constitution. By blocking Chat GPT, the Garante could be infringing upon this fundamental right, as it restricts citizens’ access to a tool that can provide valuable information and insights. It raises the question of whether the Garante’s decision may be overstepping its mandate and interfering with citizens’ constitutional rights.

In conclusion, the situation surrounding Chat GPT in Italy is multifaceted, involving geopolitical dynamics, European power struggles, and questions around the consistency of data protection measures. It’s crucial to consider all these factors when examining this event and its implications for Data Protection and AI regulation and international relations. 

Why Zero Trust is the present and Future of Cybersecurity

Photo by Tima Miroshnichenko from Pexels

As cyber threats continue to evolve and become more sophisticated, traditional security models are no longer sufficient to protect organizations from data breaches and other security incidents.

Zero trust, an approach to security that assumes all users, devices, and applications are untrusted and continuously verifies access, is gaining popularity as a more effective way to reduce risk and protect sensitive data.

To implement a Zero Trust strategy, you must assume to be compromised: One of the main tenets of zero trust is to assume that the infrastructure is already compromised. This means that the architecture must be designed in a way that even if compromised, the risk is still reduced as much as possible.

Here are some key points to consider when implementing a zero trust architecture:

  1. VPNs are a thing of the past: Traditional VPNs provide a secure connection to the corporate network, but they also create a large attack surface and can be a source of vulnerabilities. Zero trust alternatives, such as software-defined perimeters, provide a more secure way to access resources without exposing the network to potential threats.
  2. Zero trust applies to devices and identities: Zero trust is not just about securing the network perimeter; it also includes securing individual devices and verifying user identities. This can be achieved through technologies such as risk-based multi-factor authentication and device trust.
  3. Zero trust can and should be integrated with Extended Detection and Response (XDR) to allow an improvement of detection and response capabilities. The integration of XDR with Zero Trust is a topic that deserves its own in-depth exploration. Stay tuned for a follow-up article dedicated to exploring the benefits and considerations of integrating Zero Trust with XDR.
  4. Integration with Secure Access Service Edge (SASE): Zero trust is just one piece of the puzzle when it comes to securing the modern workplace. It should be integrated with other capabilities, such as cloud security, web filtering, and threat detection, within a Secure Access Service Edge (SASE) to provide a comprehensive security solution.

Is Zero Trust the Cybersecurity Silver Bullet We All Needed?

Unfortunately, that’s not the case.

Zero trust is not just a set of tools or technologies; it requires a fundamental shift in the way organizations approach architectures, infrastructure, and security. It involves questioning assumptions about who and what can be trusted and implementing security controls that continuously monitor and verify access.

Additionally, implementing a zero trust architecture is not a one-off project. It requires ongoing monitoring and assessment to ensure that security controls remain effective and adapt to changing threats.

The good thing is that if properly implemented, zero trust will both make the organization more secure and improve user experience: Traditional security models can be cumbersome for users, but zero trust can actually enhance user experience by enabling more seamless and secure access to resources from anywhere, on any trusted device.

In conclusion, zero trust is a powerful approach to security that can help organizations reduce risk and protect sensitive data in an increasingly complex threat landscape. By implementing a zero trust architecture that includes a shift in mindset, continuous monitoring and assessment, integration with XDR, and other security capabilities within a SASE, organizations can stay ahead of potential threats and provide a more secure environment for their employees and customers.

Newer posts »

© 2026 CyberSec.Cafe