<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Heidy Khlaaf on The Trail of Bits Blog</title><link>https://miscreants.github.io/blog.trailofbits.com/authors/heidy-khlaaf/</link><description>Recent content in Heidy Khlaaf on The Trail of Bits Blog</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Tue, 16 Jan 2024 12:00:39 -0500</lastBuildDate><atom:link href="https://miscreants.github.io/blog.trailofbits.com/authors/heidy-khlaaf/index.xml" rel="self" type="application/rss+xml"/><item><title>LeftoverLocals: Listening to LLM responses through leaked GPU local memory</title><link>https://miscreants.github.io/blog.trailofbits.com/2024/01/16/leftoverlocals-listening-to-llm-responses-through-leaked-gpu-local-memory/</link><pubDate>Tue, 16 Jan 2024 12:00:39 -0500</pubDate><guid>https://miscreants.github.io/blog.trailofbits.com/2024/01/16/leftoverlocals-listening-to-llm-responses-through-leaked-gpu-local-memory/</guid><description>We are disclosing LeftoverLocals: a vulnerability that allows recovery of data from GPU local memory created by another process on Apple, Qualcomm, AMD, and Imagination GPUs. LeftoverLocals impacts the security posture of GPU applications as a whole, with particular significance to LLMs and ML models run on impacted GPU […]</description></item><item><title>Assessing the security posture of a widely used vision model: YOLOv7</title><link>https://miscreants.github.io/blog.trailofbits.com/2023/11/15/assessing-the-security-posture-of-a-widely-used-vision-model-yolov7/</link><pubDate>Wed, 15 Nov 2023 10:15:05 -0500</pubDate><guid>https://miscreants.github.io/blog.trailofbits.com/2023/11/15/assessing-the-security-posture-of-a-widely-used-vision-model-yolov7/</guid><description>TL;DR: We identified 11 security vulnerabilities in YOLOv7, a popular computer vision framework, that could enable attacks including remote code execution (RCE), denial of service, and model differentials (where an attacker can trigger a model to perform differently in different contexts). Open-source software […]</description></item><item><title>Trail of Bits’s Response to OSTP National Priorities for AI RFI</title><link>https://miscreants.github.io/blog.trailofbits.com/2023/07/18/trail-of-bitss-response-to-ostp-national-priorities-for-ai-rfi/</link><pubDate>Tue, 18 Jul 2023 13:46:44 -0400</pubDate><guid>https://miscreants.github.io/blog.trailofbits.com/2023/07/18/trail-of-bitss-response-to-ostp-national-priorities-for-ai-rfi/</guid><description>The Office of Science and Technology Policy (OSTP) has circulated a request for information (RFI) on how best to develop policies that support the responsible development of AI while minimizing risk to rights, safety, and national security. In our response, we highlight the following points: To ensure that AI […]</description></item><item><title>Trail of Bits’s Response to NTIA AI Accountability RFC</title><link>https://miscreants.github.io/blog.trailofbits.com/2023/06/16/trail-of-bitss-response-to-ntia-ai-accountability-rfc/</link><pubDate>Fri, 16 Jun 2023 08:00:10 -0400</pubDate><guid>https://miscreants.github.io/blog.trailofbits.com/2023/06/16/trail-of-bitss-response-to-ntia-ai-accountability-rfc/</guid><description>The National Telecommunications and Information Administration (NTIA) has circulated an Artificial Intelligence (AI) Accountability Policy Request for Comment on what policies can support the development of AI audits, assessments, certifications, and other mechanisms to create earned trust in AI systems. Trail of Bits has submitted a response to the […]</description></item></channel></rss>