<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Suha Sabi Hussain on The Trail of Bits Blog</title><link>https://miscreants.github.io/blog.trailofbits.com/authors/suha-sabi-hussain/</link><description>Recent content in Suha Sabi Hussain on The Trail of Bits Blog</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Thu, 21 Aug 2025 00:00:00 -0400</lastBuildDate><atom:link href="https://miscreants.github.io/blog.trailofbits.com/authors/suha-sabi-hussain/index.xml" rel="self" type="application/rss+xml"/><item><title>Weaponizing image scaling against production AI systems</title><link>https://miscreants.github.io/blog.trailofbits.com/2025/08/21/weaponizing-image-scaling-against-production-ai-systems/</link><pubDate>Thu, 21 Aug 2025 07:00:00 -0400</pubDate><guid>https://miscreants.github.io/blog.trailofbits.com/2025/08/21/weaponizing-image-scaling-against-production-ai-systems/</guid><description>In this blog post, we’ll detail how attackers can exploit image scaling on Gemini CLI, Vertex AI Studio, Gemini’s web and API interfaces, Google Assistant, Genspark, and other production AI systems. We’ll also explain how to mitigate and defend against these attacks, and we’ll introduce Anamorpher, our open-source tool that lets you explore and generate these crafted images.</description></item><item><title>Hijacking multi-agent systems in your PajaMAS</title><link>https://miscreants.github.io/blog.trailofbits.com/2025/07/31/hijacking-multi-agent-systems-in-your-pajamas/</link><pubDate>Thu, 31 Jul 2025 09:00:00 -0400</pubDate><guid>https://miscreants.github.io/blog.trailofbits.com/2025/07/31/hijacking-multi-agent-systems-in-your-pajamas/</guid><description>We’re releasing pajaMAS: a curated set of MAS hijacking demos that illustrate important principles of MAS security.</description></item><item><title>Relishing new Fickling features for securing ML systems</title><link>https://miscreants.github.io/blog.trailofbits.com/2024/03/04/relishing-new-fickling-features-for-securing-ml-systems/</link><pubDate>Mon, 04 Mar 2024 09:00:44 -0500</pubDate><guid>https://miscreants.github.io/blog.trailofbits.com/2024/03/04/relishing-new-fickling-features-for-securing-ml-systems/</guid><description>We’ve added new features to Fickling to offer enhanced threat detection and analysis across a broad spectrum of machine learning (ML) workflows. Fickling is a decompiler, static analyzer, and bytecode rewriter for the Python pickle module that can help you detect, analyze, or create malicious pickle files. While the ML community […]</description></item><item><title>Assessing the security posture of a widely used vision model: YOLOv7</title><link>https://miscreants.github.io/blog.trailofbits.com/2023/11/15/assessing-the-security-posture-of-a-widely-used-vision-model-yolov7/</link><pubDate>Wed, 15 Nov 2023 10:15:05 -0500</pubDate><guid>https://miscreants.github.io/blog.trailofbits.com/2023/11/15/assessing-the-security-posture-of-a-widely-used-vision-model-yolov7/</guid><description>TL;DR: We identified 11 security vulnerabilities in YOLOv7, a popular computer vision framework, that could enable attacks including remote code execution (RCE), denial of service, and model differentials (where an attacker can trigger a model to perform differently in different contexts). Open-source software […]</description></item><item><title>Secure your machine learning with Semgrep</title><link>https://miscreants.github.io/blog.trailofbits.com/2022/10/03/semgrep-maching-learning-static-analysis/</link><pubDate>Mon, 03 Oct 2022 09:00:53 -0400</pubDate><guid>https://miscreants.github.io/blog.trailofbits.com/2022/10/03/semgrep-maching-learning-static-analysis/</guid><description>tl;dr: Our publicly available Semgrep ruleset now has 11 rules dedicated to the misuse of machine learning libraries. Try it out now! Picture this: You’ve spent months curating images, trying out different architectures, downloading pretrained models, messing with Kubernetes, and you’re finally ready to ship your sparkling new machine learning (ML) product. […]</description></item><item><title>PrivacyRaven Has Left the Nest</title><link>https://miscreants.github.io/blog.trailofbits.com/2020/10/08/privacyraven-has-left-the-nest/</link><pubDate>Thu, 08 Oct 2020 08:00:36 -0400</pubDate><guid>https://miscreants.github.io/blog.trailofbits.com/2020/10/08/privacyraven-has-left-the-nest/</guid><description>If you work on deep learning systems, check out our new tool, PrivacyRaven—it’s a Python library that equips engineers and researchers with a comprehensive testing suite for simulating privacy attacks on deep learning systems. Because deep learning enables software to perform tasks without explicit programming, it’s become ubiquitous in […]</description></item></channel></rss>