thomas_bonner Profile Banner
Tom Bonner Profile
Tom Bonner

@thomas_bonner

Followers
1K
Following
2K
Media
64
Statuses
507

SVP of Research @hiddenlayersec. Formerly Norman, HP, Cylance, BlackBerry. All views are my own.

England, United Kingdom
Joined December 2009
Don't wanna be here? Send us removal request.
@thomas_bonner
Tom Bonner
3 months
RT @4a696d: So this one has been a while coming. If you've seen any of the talks or workshops I've done recently you'll have heard me talki….
0
5
0
@thomas_bonner
Tom Bonner
4 months
Announcing our latest attack technique, "Policy Puppetry" - a single, transferable prompt blending structured policy & roleplay that bypasses alignment in frontier AI models. Game-changing for red-teaming!. #AI #GenAI #RedTeam #CyberSecurity .
Tweet card summary image
hiddenlayer.com
HiddenLayer’s latest research uncovers a universal prompt injection bypass impacting GPT-4, Claude, Gemini, and more, exposing major LLM security gaps.
1
1
6
@thomas_bonner
Tom Bonner
7 months
RT @hiddenlayersec: HiddenLayer researchers uncovered a malicious version of the Android #DeepSeek - #AI Assistant app recently uploaded to….
0
2
0
@thomas_bonner
Tom Bonner
11 months
Our latest research, modifying the computational graphs of neural networks to introduce backdoors, has been extremely interesting. In this blog, we've targeted ResNet, YOLO, and Phi-3 models, using different triggers and payloads. #AI #CyberSecurity.
hiddenlayer.com
The HiddenLayer SAI team has discovered a novel method for creating backdoors in neural network models dubbed ‘ShadowLogic’.
0
2
4
@thomas_bonner
Tom Bonner
1 year
RT @hiddenlayersec: Today, we publicly disclosed 14 new CVEs across three critical machine learning projects. These vulnerabilities highlig….
0
2
0
@thomas_bonner
Tom Bonner
1 year
RT @hiddenlayersec: 🚨 New Research: AI’ll Be Watching You . Our team recently presented this cutting-edge research at @aivillage_dc 2024. T….
0
1
0
@thomas_bonner
Tom Bonner
1 year
RT @craiu: Small thread about my experience YARA-X, version 0.3.0 fresh beta, courtesy of @plusvic.
0
38
0
@thomas_bonner
Tom Bonner
1 year
RT @Abraxus7331: I'm incredibly excited to announce that I will be speaking with @thomas_bonner this August at #BHUSA. If you enjoyed the r….
0
1
0
@thomas_bonner
Tom Bonner
1 year
Very nice work from @Abraxus7331 and @KieranEvans89 in discovering CVE-2024-27322, a vulnerability in R's deserialization library that can lead to "R-bitrary" code execution when deserializing untrusted data.
Tweet card summary image
hiddenlayer.com
HiddenLayer uncovered a zero-day deserialization vulnerability in the popular programming language R, widely used within government and medical research that could result in a supply chain attack.
1
6
15
@thomas_bonner
Tom Bonner
2 years
RT @trailofbits: Fickling gets powerful new upgrades: a modular analysis API and PyTorch and Polyglot modules. Enhance threat detection and….
0
12
0
@thomas_bonner
Tom Bonner
2 years
RT @TheHackersNews: 🤖 Security researchers have uncovered a new #vulnerability in Hugging Face's Safetensors conversion service that could….
Tweet card summary image
thehackernews.com
Hugging Face vulnerability allows attackers to hijack machine learning models.
0
34
0
@thomas_bonner
Tom Bonner
2 years
Our researchers discovered that the Hugging Face PyTorch to Safetensors conversion service could easily be compromised by attackers, who could tamper with models and leak the token used to create pull requests from the official bot.
Tweet card summary image
hiddenlayer.com
In this blog, we show how an attacker could compromise the Hugging Face Safetensors conversion space and its associated service bot.
0
12
18
@thomas_bonner
Tom Bonner
2 years
RT @hiddenlayersec: In our SAI team's latest blog, they discuss and demonstrate how easily preventable, high-impact vulnerabilities known i….
Tweet card summary image
hiddenlayer.com
HiddenLayer's SAI Team takes a look into how MLOps platform companies need more secure development practices and better security testing due to their widespread usage.
0
6
0
@thomas_bonner
Tom Bonner
2 years
RT @hiddenlayersec: We’re excited to share the launch of the @hiddenlayersec Partner Program, marking a significant milestone in extending….
0
3
0
@thomas_bonner
Tom Bonner
2 years
RT @CVEannounce: HiddenLayer is now a CVE Numbering Authority (CNA) assigning CVE IDs all @hiddenlayersec systems, services, & products + v….
0
4
0