Rich Harang

@rharang
634 Followers
379 Following
14 Posts

ML and security; using bad guys to catch math since 2010.

Now: Principal Security Architect (AI/ML) @ NVIDIA.
Previously: Duo (Algorithms Research team lead), Sophos/Invincea (Research director), US Army Research Laboratory (team lead).

Я очень серьезный специалист по кибербезопасности, это очевидно так как этот цитат по-русский.

He/him; personal account and opinions.

We strayed from the light of god when we stopped calling it 'yolo mode'.
lord save us from "AI Alignment Scholars" scaring each other with spooky stories that somehow find their way into policy
Langchain's llm-math module literally just uses `eval` under the hood. It's literally zero-effort RCE. I'm embarrassed to even share this as an "attack", but *people keep using it*. For Christ's sake can we deal with this nonsense before we start worrying about AGI murderbots?
I am once again begging corporations to run any and all copy past twelve-year-old boys to see if they start snickering uncontrollably before going live with it.

Just a reminder for folks out there that you can do meaningful, impactful, and (yes) well-paid work in ML without needing a PhD, let alone the doorstop CVs full of top-tier conference papers that ML grads from the prestigious programs all seem to have these days.

Domain expertise, knowing the non-ML state of the art, knowing what problems to solve, and knowing what counts as a good-enough solution are all *much* more valuable than ICML publications. Don't let people tell you otherwise.

All these articles suddenly about "Oh it's time to start masking indoors again" and I'm here like "what's 'again'?"
I am enjoying Mastodon, but was trying to explain it at dinner and someone said that, in the limit, it sounded like RSS done the hard way, and, man, I'm still salty about google reader.

Leave Twitter just because it keeps failing at random in completely unpredictable ways, the decision-making process is utterly opaque resisting any rational explanation, and it's occasionally deeply racist for no obvious reason?

My dude, I work in machine learning.

#MLSec

What I've learned so far about using Mastodon in the #twittermigration:
- You can't do content search on posts for anyone but yourself and people you follow, only hashtags
- ...and so hashtags are big for visibility (if that's what you want)
- There's a tweetdeck-ish interface ("advanced web interface") for desktop browsers under Preferences->Appearance
- DMs appear to sent like normal posts (no separate UI), but you have to @ your recipient and set visibility to "mentioned people only" (image)