• bitcoinBitcoin(BTC)$79,159.000.95%
  • ethereumEthereum(ETH)$2,500.031.33%
  • tetherTether(USDT)$1.00-0.01%
  • binancecoinBNB(BNB)$753.900.74%
  • rippleXRP(XRP)$1.433.66%
  • usd-coinUSDC(USDC)$1.000.01%
  • solanaSolana(SOL)$104.561.85%
  • tronTRON(TRX)$0.3389690.50%
  • Figure HelocFigure Heloc(FIGR_HELOC)$1.040.00%
  • zcashZcash(ZEC)$1,229.538.88%
  • HyperliquidHyperliquid(HYPE)$86.633.60%
  • dogecoinDogecoin(DOGE)$0.0904521.38%
  • RainRain(RAIN)$0.016061-1.02%
  • USDSUSDS(USDS)$1.000.00%
  • whitebitWhiteBIT Coin(WBT)$81.917.95%
  • moneroMonero(XMR)$502.30-2.68%
  • chainlinkChainlink(LINK)$12.57-0.23%
  • leo-tokenLEO Token(LEO)$9.18-0.49%
  • cardanoCardano(ADA)$0.2207782.01%
  • stellarStellar(XLM)$0.1899120.34%
  • bitcoin-cashBitcoin Cash(BCH)$259.060.82%
  • daiDai(DAI)$1.00-0.01%
  • Ethena USDeEthena USDe(USDE)$1.000.02%
  • uniswapUniswap(UNI)$6.95-1.47%
  • CantonCanton(CC)$0.1082073.04%
  • USD1USD1(USD1)$1.000.00%
  • litecoinLitecoin(LTC)$54.48-0.59%
  • the-open-networkGram (prev. Toncoin)(GRAM)$1.401.31%
  • hedera-hashgraphHedera(HBAR)$0.079361-1.56%
  • avalanche-2Avalanche(AVAX)$8.02-0.17%
  • suiSui(SUI)$0.821.19%
  • Global DollarGlobal Dollar(USDG)$1.000.02%
  • shiba-inuShiba Inu(SHIB)$0.0000051.23%
  • nearNEAR Protocol(NEAR)$2.394.98%
  • crypto-com-chainCronos(CRO)$0.0596153.74%
  • paypal-usdPayPal USD(PYUSD)$1.000.01%
  • BlackRock USD Institutional Digital Liquidity FundBlackRock USD Institutional Digital Liquidity Fund(BUIDL)$1.000.00%
  • tether-goldTether Gold(XAUT)$4,397.08-0.16%
  • MemeCoreMemeCore(M)$1.18-0.01%
  • Circle USYCCircle USYC(USYC)$1.140.01%
  • BittensorBittensor(TAO)$259.101.85%
  • Ripple USDRipple USD(RLUSD)$1.000.00%
  • okbOKB(OKB)$114.63-0.47%
  • Ondo US Dollar YieldOndo US Dollar Yield(USDY)$1.14-0.15%
  • mantleMantle(MNT)$0.642.56%
  • AsterAster(ASTER)$0.760.10%
  • polkadotPolkadot(DOT)$1.1811.26%
  • aaveAave(AAVE)$129.80-0.90%
  • pax-goldPAX Gold(PAXG)$4,401.56-0.11%
  • Pump.funPump.fun(PUMP)$0.00456410.33%
TradePoint.io
  • Main
  • AI & Technology
  • Stock Charts
  • Market & News
  • Business
  • Finance Tips
  • Trade Tube
  • Blog
  • Shop
No Result
View All Result
TradePoint.io
No Result
View All Result

How Risky Is Your Open-Source LLM Project? A New Research Explains The Risk Factors Associated With Open-Source LLMs

July 8, 2023
in AI & Technology
Reading Time: 5 mins read
A A
How Risky Is Your Open-Source LLM Project? A New Research Explains The Risk Factors Associated With Open-Source LLMs
ShareShareShareShareShare

Large Language Models (LLMs) and Generative AI, such as GPT engines, have been creating big waves in the AI domain recently, and there is a big hype in the market, both among retail individuals and corporates, to ride this new tech wave. However, as this technology is rapidly taking over multiple use cases in the market, we need to pay more attention to the security aspects of it and pay attention in greater detail to the risk associated with its usage, especially the open-source LLMs. 

In recent research conducted by Rezilion, a renowned automated software supply chain security platform, experts have investigated this exact issue, and the findings will surprise us. They considered all the projects that fit these criteria:

  1. Projects must have been created eight months ago or less (approx November 2022, to June 2023, at the time of this paper’s publication) 
  2. Projects are related to the topics: LLM, ChatGPT, Open-AI, GPT-3.5, or GPT-4 
  3. Projects must have at least 3,000 stars on GitHub. 

These criteria have ensured that all the major projects come under the research. 

[Sponsored] 🔥 Build your personal brand with Taplio  🚀 The 1st all-in-one AI-powered tool to grow on LinkedIn. Create better LinkedIn content 10x faster, schedule, analyze your stats & engage. Try it for free!

To articulate their research, they have used a framework called OpenSSF Scorecard. Scorecard is a SAST tool created by the Open Source Security Foundation (OSSF). Its goal is to assess the security of open-source projects and help improve them. The assessment is based on different facts about the repository, such as its number of vulnerabilities, how often it’s being maintained, if it contains binary files and many more.

The purpose of all the checks together is to ensure adherence to security best practices and industry standards. Each check has a risk level associated with it. The risk level represents the estimated risk associated with not adhering to a specific best practice and adds weight to the score accordingly.

Currently, 18 checks can be divided into three themes: holistic security practices, source code risk assessment, and build process risk assessment. The OpenSSF Scorecard assigns an ordinal score between 0 to 10 and a risk level score for each check.

It turns out that almost all of these LLMs (open-sourced) and projects deal with major security concerns, which the experts have categorized as follows:

1.Trust boundary risk 

Risks such as inadequate sandboxing, unauthorized code execution, SSRF vulnerabilities, insufficient access controls, and even prompt injections fall under the general concept of trust boundaries.

Anyone can inject any malicious nlp masked command, which can cross multiple channels and severely affect the entire software chain.

One of the popular examples is CVE-2023-29374 Vulnerability in LangChain (3rd most popular open source gpt)

2. Data management Risk 

Data leakage and training data poisoning fall under the data management risks category. These risks pertain to any machine-learning system and are not just restricted to Large Language Models.

Training data poisoning refers to deliberately manipulating an LLM’s training data or fine-tuning procedures by an attacker to introduce vulnerabilities, backdoors, or biases that can undermine the model’s security, effectiveness, or ethical behavior. This malicious act aims to compromise the integrity and reliability of the LLM by injecting misleading or harmful information during the training process.

 3. Inherent Model Risk

These security concerns occur due to the limitation of the underlying ML model: inadequate AI alignment and overreliance on LLM-generated content.

 4. Basic Security Best Practices

It consists of issues such as improper error handling or insufficient access controls that fall under general security best practices. They are common not to machine learning models in general and not specifically to LLMs.

The astonishing and concerning fact is the security score all these models have received. The average score among the checked projects was just 4.6 out of 10, the average age was 3.77 months, and the average number of stars was 15,909. The projects that gain popularity comparatively quickly are much more at risk than those built over a long period. 

The company has not only highlighted the security issues these projects are dealing with right now but has also extensively suggested the steps in their research that can be taken to mitigate these risks and make them safer in the longer run. 

In conclusion, the company has highlighted the need for security protocols to be properly administered and ensured, has highlighted the specific security weak points, and has suggested changes that can be done to eradicate such risks. By taking comprehensive risk assessments and robust security measures, organizations can harness the power of open-source LLMs while protecting sensitive information and maintaining a secure environment.


Don’t forget to join our 25k+ ML SubReddit, Discord Channel, and Email Newsletter, where we share the latest AI research news, cool AI projects, and more. If you have any questions regarding the above article or if we missed anything, feel free to email us at [email protected]

🚀 Check Out 100’s AI Tools in AI Tools Club


References:

  • https://www.darkreading.com/tech-trends/open-source-llm-project-insecure-risky-use
  • https://info.rezilion.com/explaining-the-risk-exploring-the-large-language-models-open-source-security-landscape


YOU MAY ALSO LIKE

Meta Introduces Muse, a Personal AI Agent That Runs on Its Own Dedicated Secure Cloud Computer

NSA, CISA, FBI Warn China-Based AI Firms Distill US Frontier Models – Unite.AI

Anant is a Computer science engineer currently working as a data scientist with experience in Finance and AI products as a service. He is keen to build AI-powered solutions that create better data points and solve daily life problems in an impactful and efficient way.


🔥 StoryBird.ai just dropped some amazing features. Generate an illustrated story from a prompt. Check it out here. (Sponsored)

Credit: Source link

ShareTweetSendSharePin

Related Posts

Meta Introduces Muse, a Personal AI Agent That Runs on Its Own Dedicated Secure Cloud Computer
AI & Technology

Meta Introduces Muse, a Personal AI Agent That Runs on Its Own Dedicated Secure Cloud Computer

September 9, 2026
NSA, CISA, FBI Warn China-Based AI Firms Distill US Frontier Models – Unite.AI
AI & Technology

NSA, CISA, FBI Warn China-Based AI Firms Distill US Frontier Models – Unite.AI

September 9, 2026
How To Change And Customize Your Apple CarPlay Display
AI & Technology

How To Change And Customize Your Apple CarPlay Display

September 8, 2026
Is There Any Benefit To Restarting Your PC Regularly?
AI & Technology

Is There Any Benefit To Restarting Your PC Regularly?

September 8, 2026
Next Post
Dow Making Sure Products Have Potential to Be Fully Recyclable, CEO Says

Dow Making Sure Products Have Potential to Be Fully Recyclable, CEO Says

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Search

No Result
View All Result
Stay Tuned NOW Streaming Behind The Scenes! – Jul 21

Stay Tuned NOW Streaming Behind The Scenes! – Jul 21

September 7, 2026
Global Forex Shifts: Yen Carry Trade Unwinds Amid Policy Divergence

Global Forex Shifts: Yen Carry Trade Unwinds Amid Policy Divergence

September 7, 2026
Tax-Loss Harvesting Can Offset Your Capital Gains Tax

Tax-Loss Harvesting Can Offset Your Capital Gains Tax

September 7, 2026

About

Learn more

Our Services

Legal

Privacy Policy

Terms of Use

Bloggers

Learn more

Article Links

Contact

Advertise

Ask us anything

©2020- TradePoint.io - All rights reserved!

Tradepoint.io, being just a publishing and technology platform, is not a registered broker-dealer or investment adviser. So we do not provide investment advice. Rather, brokerage services are provided to clients of Tradepoint.io by independent SEC-registered broker-dealers and members of FINRA/SIPC. Every form of investing carries some risk and past performance is not a guarantee of future results. “Tradepoint.io“, “Instant Investing” and “My Trading Tools” are registered trademarks of Apperbuild, LLC.

This website is operated by Apperbuild, LLC. We have no link to any brokerage firm and we do not provide investment advice. Every information and resource we provide is solely for the education of our readers. © 2020 Apperbuild, LLC. All rights reserved.

No Result
View All Result
  • Main
  • AI & Technology
  • Stock Charts
  • Market & News
  • Business
  • Finance Tips
  • Trade Tube
  • Blog
  • Shop

© 2023 - TradePoint.io - All Rights Reserved!