A trained model represents enormous investment in compute, data, and expertise. The threat of model theft — through extraction, distillation, or outright weight exfiltration — is real and increasingly operationalised. Here is the threat landscape and the realistic protections.
Martynas Vareikis
Add a small, carefully chosen perturbation to an image and a state-of-the-art classifier sees a school bus instead of a panda. Adversarial examples are the longest-running unresolved problem in machine-learning security and increasingly relevant to deployed systems.
An AIBOM lists everything that went into producing an AI model — base model, training data, fine-tuning corpora, dependencies, evaluation results. The concept is borrowed from software supply-chain security and increasingly required by regulators. Here is what an AIBOM actually contains and why it matters.
Pre-LLM phishing was constrained by language. Post-LLM phishing is not. The result is a measurable upgrade in lure quality, a wider reach into non-English-speaking markets, and an emerging class of personalised attacks that were previously economically unviable.
Deepfake video and AI voice cloning have moved from research demos to operational tools used in fraud, fraud-driven CEO scams, election interference, and harassment. Here is the actual state of the technology, the real incidents, and what defences exist.
AI is now in nearly every security product’s marketing copy. Some of it has changed the game; some of it has not changed anything. Here is a category-by-category honest assessment of where machine learning has actually moved the security needle and where the marketing has run ahead of the technology.
Prompt injection is the SQL injection of the LLM era — easy to demonstrate, hard to fully defend against, and present in essentially every commercial LLM application. Here is what it is, why it persists, and the realistic mitigation playbook.