VOOZH about

URL: https://thenewstack.io/ai-llms-and-security-how-to-deal-with-the-new-threats/

⇱ AI, LLMs and Security: How to Deal with the New Threats  - The New Stack


TNS
SUBSCRIBE
Join our community of software engineering leaders and aspirational developers. Always stay in-the-know by getting the most important news and exclusive content delivered fresh to your inbox to learn more about at-scale software development.
REQUIRED
It seems that you've previously unsubscribed from our newsletter in the past. Click the button below to open the re-subscribe form in a new tab. When you're done, simply close that tab and continue with this form to complete your subscription.
The New Stack does not sell your information or share it with unaffiliated third parties. By continuing, you agree to our Terms of Use and Privacy Policy.
Welcome and thank you for joining The New Stack community!
Please answer a few simple questions to help us deliver the news and resources you are interested in.
REQUIRED
REQUIRED
REQUIRED
REQUIRED
REQUIRED
Great to meet you!
Tell us a bit about your job so we can cover the topics you find most relevant.
REQUIRED
REQUIRED
REQUIRED
REQUIRED
REQUIRED
Welcome!

We’re so glad you’re here. You can expect all the best TNS content to arrive Monday through Friday to keep you on top of the news and at the top of your game.

What’s next?

Check your inbox for a confirmation email where you can adjust your preferences and even join additional groups.

Follow TNS on your favorite social media networks.

Become a TNS follower on LinkedIn.

Check out the latest featured and trending stories while you wait for your first TNS newsletter.

PREV
1 of 2
NEXT
VOXPOP
As a JavaScript developer, what non-React tools do you use most often?
Angular
0%
Astro
0%
Svelte
0%
Vue.js
0%
Other
0%
I only use React
0%
I don't use JavaScript
0%
Thanks for your opinion! Subscribe below to get the final results, published exclusively in our TNS Update newsletter:
NEW! Try Stackie AI
From clobbered drafts to real-time sync
Apr 14th 2026 10:00am, by David Moore
TypeScript 6.0 RC arrives as a bridge to a faster future
Mar 14th 2026 9:00am, by Darryl K. Taft
Mastra empowers web devs to build AI agents in TypeScript
Jan 28th 2026 11:00am, by Loraine Lawson
2024-04-11 08:20:12
AI, LLMs and Security: How to Deal with the New Threats 
podcast,video,
AI / Large Language Models / Security

AI, LLMs and Security: How to Deal with the New Threats 

When experimenting with AI, watch out for vulnerabilities that could be targets of attack, say Chris Pirillo and Lance Seidman in this episode of The New Stack Makers.
Apr 11th, 2024 8:20am by Chris Pirillo
👁 Featued image for: AI, LLMs and Security: How to Deal with the New Threats 

By now, most of the galaxy has used an AI tool in one way or another — with most people content in not going beyond trying one or two tools within their respective web browsers. But have you found yourself installing a large language model (LLM) on a local machine to tickle your tinkering inclinations?

If so, be careful. In rushing to try a new LLM, you might be exposing yourself to security risks. As AI continues to advance, so do the risks associated with potential exploits and vulnerabilities.

AI models, particularly those with millions or even billions of parameters, are highly intricate and difficult to scrutinize fully. This complexity makes them susceptible to exploitation, as attackers may find loopholes or vulnerabilities that go unnoticed by developers.

On this episode of The New Stack Makers, I had a chat with Lance Seidman to shed more light on the new security challenges. Seidman, an experienced programmer currently pursuing AI solutions to benefit healthcare practices, helped us dive into the nuances of such recent exploits.

AI Models Need Human Oversight

Hugging Face bills itself as “the platform where the machine learning community collaborates on models, datasets, and applications” — and it certainly has become the go-to place for both running demos live and downloading code to run elsewhere.

Recently, it was discovered (and subsequently addressed) that malicious AI models on Hugging Face were backdooring users’ machines — contingent, seemingly, on Python’s pickle module.

Pickle, a serialization module in Python, allowed attackers to manipulate AI models to execute arbitrary commands, posing significant security threats to users. To mitigate, Hugging Face implemented a security scanner that scans every file pushed to the Hub and runs security checks. At this time, that includes both ClamAV scans and Pickle Import scans.

But nothing is foolproof.  One of the key takeaways from our conversation with Seidman is the critical role of human oversight in safeguarding AI systems against malicious attacks. While AI models may possess impressive capabilities, they are not immune to social engineering tactics.

In this episode of Makers, Seidman demonstrated how AI can be tricked into providing information on potential exploits, highlighting the need for constant vigilance and proactive security measures.

He noted: “Of course, before the AI creates new AI to make things better and make someone like me obsolete, there still needs to be some human at some point to just make sure things are being done correctly,” Seidman said in the episode.

“Because these models and all this information is created thanks to human intelligence. So, it only knows as much as it knows from us. At the same time, as we know, right now, these things get skewed and there’s misinformation — and somebody needs to be monitoring it. So, that’s probably a job in itself.”

Technical Safeguards, Cultural Awareness

As AI technologies become more sophisticated, so too do the tactics employed by malicious actors. To address these challenges, Seidman advocated for a multi-faceted approach to AI security. This approach involves not only technical safeguards but also fostering a culture of awareness and accountability within the AI community. Developers must prioritize security at every stage of the development life cycle, from code creation to deployment and beyond.

In all seriousness, use your noodle. Don’t outsource your critical thinking skills. That’s the bottom line.

One of the critical tools in the arsenal of AI security professionals is the ability to detect and mitigate potential exploits before they can be exploited. In this episode, Seidman further demonstrated how AI can be used to identify vulnerabilities, and how to address those weak spots before they can be exploited. By leveraging AI for defensive purposes, security professionals can stay one step ahead of potential threats and protect their systems from harm.

Check out the full episode for more on how to keep your organization safe when using AI.

You can also download The New Stack’s latest ebook, “Better, Faster, Stronger: How Generative AI Transforms Software Development,” for a clear-eyed view of the advantages and challenges baked into GenAI.

👁 Image

TRENDING STORIES
Chris Pirillo has been producing content since the advent of the internet, informing and entertaining audiences through all forms of media (since before graphical web browsers became a thing). With a passion for catalyzing critical conversations, Chris enjoys exploring trending...
Read more from Chris Pirillo
SHARE THIS STORY
TRENDING STORIES
SHARE THIS STORY
TRENDING STORIES
TNS DAILY NEWSLETTER Receive a free roundup of the most recent TNS articles in your inbox each day.
The New Stack does not sell your information or share it with unaffiliated third parties. By continuing, you agree to our Terms of Use and Privacy Policy.