Sign up to save tools and stay up to date with the latest in AI
bg
bg
1

Google expands its bug bounty program to target generative AI attacks

Oct 26, 2023 - engadget.com
Google has expanded its Vulnerability Rewards Program (VRP) to focus on AI-specific attacks and potential malicious uses. The company has released updated guidelines to clarify which discoveries qualify for rewards. For instance, the discovery of training data extraction that leaks private, sensitive information is within the scope, but if it only reveals public, non-sensitive data, it would not qualify for a reward. Google gave $12 million to security researchers for bug discoveries last year.

The company stated that AI presents different security issues than other technologies, such as model manipulation and unfair bias, hence the need for new guidelines. Google believes that the VRP expansion will encourage research on AI safety and security, and highlight potential issues, making AI safer for everyone. The expansion also precedes a "sweeping" executive order from President Biden, reportedly scheduled for October 30, which would impose strict assessments and requirements for AI models before they can be used by government agencies.

Key takeaways:

  • Google is expanding its Vulnerability Rewards Program (VRP) to focus on AI-specific attacks and potential malicious uses, with updated guidelines on what discoveries qualify for rewards.
  • The company believes this expansion will incentivize research around AI safety and security, and help uncover potential issues to make AI safer for everyone.
  • Google is also expanding its open source security work to make information about AI supply chain security universally discoverable and verifiable.
  • The expansion of Google's VRP comes ahead of a reported executive order from President Biden, which would create strict assessments and requirements for AI models before they can be used by government agencies.
View Full Article

Comments (0)

Be the first to comment!