
Tom Bonner
@thomas_bonner
Followers
1K
Following
2K
Media
64
Statuses
507
SVP of Research @hiddenlayersec. Formerly Norman, HP, Cylance, BlackBerry. All views are my own.
England, United Kingdom
Joined December 2009
RT @4a696d: So this one has been a while coming. If you've seen any of the talks or workshops I've done recently you'll have heard me talki….
0
5
0
Announcing our latest attack technique, "Policy Puppetry" - a single, transferable prompt blending structured policy & roleplay that bypasses alignment in frontier AI models. Game-changing for red-teaming!. #AI #GenAI #RedTeam #CyberSecurity .
hiddenlayer.com
HiddenLayer’s latest research uncovers a universal prompt injection bypass impacting GPT-4, Claude, Gemini, and more, exposing major LLM security gaps.
1
1
6
RT @hiddenlayersec: HiddenLayer researchers uncovered a malicious version of the Android #DeepSeek - #AI Assistant app recently uploaded to….
0
2
0
Our latest research, modifying the computational graphs of neural networks to introduce backdoors, has been extremely interesting. In this blog, we've targeted ResNet, YOLO, and Phi-3 models, using different triggers and payloads. #AI #CyberSecurity.
hiddenlayer.com
The HiddenLayer SAI team has discovered a novel method for creating backdoors in neural network models dubbed ‘ShadowLogic’.
0
2
4
RT @SecurityWeek: ShadowLogic Attack Targets AI Model Graphs to Create Codeless Backdoors
securityweek.com
HiddenLayer details ShadowLogic, a new method of creating codeless backdoors in AI models by manipulating their graphs.
0
3
0
RT @hiddenlayersec: Today, we publicly disclosed 14 new CVEs across three critical machine learning projects. These vulnerabilities highlig….
0
2
0
RT @hiddenlayersec: 🚨 New Research: AI’ll Be Watching You . Our team recently presented this cutting-edge research at @aivillage_dc 2024. T….
0
1
0
RT @Abraxus7331: I'm incredibly excited to announce that I will be speaking with @thomas_bonner this August at #BHUSA. If you enjoyed the r….
0
1
0
RT @TheHackersNews: 👨💻🔐 A new security #vulnerability (CVE-2024-27322) has been discovered in the R #programming language. It could allow….
thehackernews.com
A critical vulnerability (CVE-2024-27322) has been discovered in the R programming language. It could allow attackers to execute arbitrary code.
0
87
0
Very nice work from @Abraxus7331 and @KieranEvans89 in discovering CVE-2024-27322, a vulnerability in R's deserialization library that can lead to "R-bitrary" code execution when deserializing untrusted data.
hiddenlayer.com
HiddenLayer uncovered a zero-day deserialization vulnerability in the popular programming language R, widely used within government and medical research that could result in a supply chain attack.
1
6
15
RT @hiddenlayersec: 🎉 We are proud to present the first-ever HiddenLayer AI Threat Landscape Report! Get your copy TODAY to see our survey….
hiddenlayer.com
HiddenLayer, the leading security provider for artificial intelligence (AI) models and assets, today released its inaugural AI Threat Landscape Report highlighting the pervasive use of AI and the...
0
4
0
RT @trailofbits: Fickling gets powerful new upgrades: a modular analysis API and PyTorch and Polyglot modules. Enhance threat detection and….
0
12
0
RT @TheHackersNews: 🤖 Security researchers have uncovered a new #vulnerability in Hugging Face's Safetensors conversion service that could….
thehackernews.com
Hugging Face vulnerability allows attackers to hijack machine learning models.
0
34
0
Our researchers discovered that the Hugging Face PyTorch to Safetensors conversion service could easily be compromised by attackers, who could tamper with models and leak the token used to create pull requests from the official bot.
hiddenlayer.com
In this blog, we show how an attacker could compromise the Hugging Face Safetensors conversion space and its associated service bot.
0
12
18
RT @hiddenlayersec: 📅 SAVE THE DATE: HiddenLayer’s 2024 AI Threat Landscape Report will be released on March 6th. Sign up to be the first t….
hiddenlayer.com
As we navigate an AI-driven era, we developed this report as a practical guide to understanding the Security for AI landscape and to provide actionable steps to implement security measures at your...
0
5
0
RT @hiddenlayersec: In our SAI team's latest blog, they discuss and demonstrate how easily preventable, high-impact vulnerabilities known i….
hiddenlayer.com
HiddenLayer's SAI Team takes a look into how MLOps platform companies need more secure development practices and better security testing due to their widespread usage.
0
6
0
RT @hiddenlayersec: We’re excited to share the launch of the @hiddenlayersec Partner Program, marking a significant milestone in extending….
0
3
0
RT @hiddenlayersec: We're proud to announce that @hiddenlayersec is partnering with the CVE® Program as a CNA, which aims to identify, defi….
hiddenlayer.com
Underscoring commitment to elevating Security for AI standards AUSTIN, Texas — Dec 19, 2023 — HiddenLayer, the leading security provider for artificial intelligence (AI) models and assets, proudly...
0
3
0
RT @CVEannounce: HiddenLayer is now a CVE Numbering Authority (CNA) assigning CVE IDs all @hiddenlayersec systems, services, & products + v….
0
4
0