Month: March 2024

AI Hallucinated a Dependency. So a Cybersecurity Researcher Built It as Proof-of-Concept Malware

“Several big businesses have published source code that incorporates a software package previously hallucinated by generative AI,” the Register reported Thursday

“Not only that but someone, having spotted this reoccurring hallucination, had turned that made-up dependency into a real one, which was subsequently downloaded and installed thousands of times by developers as a result of the AI’s bad advice, we’ve learned.”

If the package was laced with actual malware, rather than being a benign test, the results could have been disastrous.

According to Bar Lanyado, security researcher at Lasso Security, one of the businesses fooled by AI into incorporating the package is Alibaba, which at the time of writing still includes a pip command to download the Python package huggingface-cli in its GraphTranslator installation instructions. There is a legit huggingface-cli, installed using pip install -U “huggingface_hub[cli]”. But the huggingface-cli distributed via the Python Package Index (PyPI) and required by Alibaba’s GraphTranslator — installed using pip install huggingface-cli — is fake, imagined by AI and turned real by Lanyado as an experiment.

He created huggingface-cli in December after seeing it repeatedly hallucinated by generative AI; by February this year, Alibaba was referring to it in GraphTranslator’s README instructions rather than the real Hugging Face CLI tool… huggingface-cli received more than 15,000 authentic downloads in the three months it has been available… “In addition, we conducted a search on GitHub to determine whether this package was utilized within other companies’ repositories,” Lanyado said in the write-up for his experiment. “Our findings revealed that several large companies either use or recommend this package in their repositories….”

Lanyado also said that there was a Hugging Face-owned project that incorporated the fake huggingface-cli, but that was removed after he alerted the biz.

“With GPT-4, 24.2 percent of question responses produced hallucinated packages, of which 19.6 percent were repetitive, according to Lanyado…”

Thanks to long-time Slashdot reader schneidafunk for sharing the article.

Read more of this story at Slashdot.

“Several big businesses have published source code that incorporates a software package previously hallucinated by generative AI,” the Register reported Thursday

“Not only that but someone, having spotted this reoccurring hallucination, had turned that made-up dependency into a real one, which was subsequently downloaded and installed thousands of times by developers as a result of the AI’s bad advice, we’ve learned.”

If the package was laced with actual malware, rather than being a benign test, the results could have been disastrous.

According to Bar Lanyado, security researcher at Lasso Security, one of the businesses fooled by AI into incorporating the package is Alibaba, which at the time of writing still includes a pip command to download the Python package huggingface-cli in its GraphTranslator installation instructions. There is a legit huggingface-cli, installed using pip install -U “huggingface_hub[cli]”. But the huggingface-cli distributed via the Python Package Index (PyPI) and required by Alibaba’s GraphTranslator — installed using pip install huggingface-cli — is fake, imagined by AI and turned real by Lanyado as an experiment.

He created huggingface-cli in December after seeing it repeatedly hallucinated by generative AI; by February this year, Alibaba was referring to it in GraphTranslator’s README instructions rather than the real Hugging Face CLI tool… huggingface-cli received more than 15,000 authentic downloads in the three months it has been available… “In addition, we conducted a search on GitHub to determine whether this package was utilized within other companies’ repositories,” Lanyado said in the write-up for his experiment. “Our findings revealed that several large companies either use or recommend this package in their repositories….”

Lanyado also said that there was a Hugging Face-owned project that incorporated the fake huggingface-cli, but that was removed after he alerted the biz.

“With GPT-4, 24.2 percent of question responses produced hallucinated packages, of which 19.6 percent were repetitive, according to Lanyado…”

Thanks to long-time Slashdot reader schneidafunk for sharing the article.

Read more of this story at Slashdot.

Read More 

Samsung archrival plans construction of world’s largest chip factory — at more than $90 billion, it will take more than 20 years to finish, so one wonders what other exciting tech will it produce

SK Hynix is to build a $90 billion chip production facility that will take 20 years to complete.

SK Hynix, Samsung’s chief competitor and the world’s number two memory maker, has begun its audacious plan to build the largest chip production facility on the planet.

The construction at SK Hynix’s giant Yongin Semiconductor Cluster in Gyeonggi Province, South Korea, will comprise four units. Work on the first unit, which is intended to be the world’s biggest three-story fabrication plant, is anticipated to commence in March 2025.

The Korea Economic Daily reports that the project is estimated to cost over 120 trillion won ($90.7 billion) and will span over two decades, with completion expected by 2046.

Government backing

The plan was first announced in 2019 but ran into delays due to Covid and licensing procedures. It received a boost in 2022 following an agreement between the government, municipalities, and companies, according to SK Hynix. The site of the first unit is now 35% prepared.

Trade Minister Ahn Deokgeun visited the site recently, promising government support for Korea’s chip industry. “All ministries will work together to ensure that Korean companies won’t lag behind global players in semiconductor manufacturing speed. We will actively support high-bandwidth memory (HBM) chips to achieve more than $120 billion in semiconductor exports this year,” he said.

The Korea Economic Daily says the government will unveil strategies to accelerate artificial intelligence chip exports and bolster semiconductor equipment by the end of June.

Creating the world’s largest chip factory is just part of SK Hynix’s future plans. The manufacturing giant is also intending to invest $4 billion to build an advanced chip packaging facility in West Lafayette, Indiana.

More from TechRadar Pro

Samsung but beats Micron to 36GB HBM3E memorySamsung archrival sells out of precious HBM cargoA glimpse at what the future of memory and storage could look like

Read More 

Scroll to top
Generated by Feedzy