Lucas Gonze (infosec posts)

46 Followers
36 Following
146 Posts

Infosec-focused account. See @lucasgonze for OSS posts.

I'm Security TPM for magmacore.org. I advise corporate clients on securing their open source open-source project . My clients include New Relic, Toyota, eBay, Cisco, and Meta.

Githubhttps://github.com/lucasgonze/
Tech bloghttps://writing.gonze.com/
Emailmailto:[email protected]?subjection=infosec.exchange
@jerry I respect your clear and calm analysis of the threat, if any, of Threads. Thank you.

Detecting Backdoors with Meta-Models

"It is widely known that it is possible to implant backdoors into neural networks, by which an attacker can choose an input to produce a particular undesirable output (e.g. misclassify an image). We propose to use meta-models, neural networks that take another network's parameters as input, to detect backdoors directly from model weights. To this end we present a meta-model architecture and train it on a dataset of ~4000 clean and backdoored CNNs trained on CIFAR-10. Our approach is simple and scalable, and is able to detect the presence of a backdoor with accuracy"

https://openreview.net/forum?id=cmJiEqniEc

#infosec #ai

Detecting Backdoors with Meta-Models

It is widely known that it is possible to implant backdoors into neural networks, by which an attacker can choose an input to produce a particular undesirable output (e.g.\ misclassify an...

OpenReview
@UncleDuke1969 Winner, Caption Contest
The best Slack channel is the "thanks" Slack channel. If your organization doesn't have one, set one up as a place for people to share praise and shout-outs and appreciation for big & small things

I was about to increase the inactivity timeout on my phone, and realized it was better to make my PIN shorter and more crackable.

If the device isn't locking on failed attempts then all is lost, and if it is locking then an extra-hard password will lead to insecure practices like a longer inactivity timeout.

@scruss
Well, some folks see a line and others see a little smudge way over near the horizon. Now where are my glasses.
@merospit @nixCraft Isn't it already possible to detect ad blockers? I know that I often get scolding from sites about my blocker.
@nixCraft Feel free to school me on how web attestation prevents ad blocking. It might be.
@nixCraft I don't see how the web attestation spec addresses ad blocking. That's not what it's about.

Most of the value of the OpenSSF Best Practices Badge and Security Scorecard is influence over your project's roadmap. You use them to find, organize, and prioritize security improvements.

But neither of those projects thinks of itself that way.

What their UX *should* be is a Kanban board for evaluating each criteria, then doing project management to mitigate work items you find.