I do stuff, I have opinions. These are not necessarily my employers opinions. I think I'm funny. I, like Mark Twain, believe that "Under certain circumstances, profanity provides a relief denied even to prayer." I also believe that "Profanity is the crutch of the inarticulate motherfucker." #fedi22 #infosec #shitposter #captainjustice Searchable via tootfinder.ch
25+ years in Cybersecurity. Redefining digital defense with a human-centric approach. Architecting Red Team operations with Sith precision, hunt metadata for sport, and believe that a bad carbonara is a critical vulnerability. 🍝🌌 Author of “Mars Attacks, Venus Hacks”: why atypical minds are the future of Threat Intelligence. I write books, I see people, I do things. 📚👥⚡
New preprint: AI_Bleeding — inference cost amplification via OOD linguistic payload
TL;DR: send queries in Grecanico or Farsi to an LLM endpoint → TTFT +59.8%, compute cost +2.8%, statistically significant. No vuln, no volumetric signature, evades all standard detection.
Worst case: exposed unauthenticated Ollama instance with num_predict=4096 + keep_alive=300s → Amplification Factor 17.56 Wh/KB. 3KB of attacker bandwidth → enough energy to charge a phone 5%.
Especially nasty for:
- PA/judicial chatbots on fixed budgets
- Pay-per-use API deployments with client-side exposed keys
- PNRR-funded public sector AI with zero inference monitoring
Four scenarios: EDoS, browser JS distribution, Ollama open-proxy relay, frontier providers as involuntary relays.
All tests on self-hosted Ollama, no commercial endpoints touched.
Paper (CC BY 4.0): https://doi.org/10.13140/RG.2.2.26767.96166
#llmsecurity #infosec #threatmodeling #ollama #ood #AI #AIResearch #aisecurity
Fan of Jazz, 🎺 and electronica. Reader of SciFi 🖖👽, unusual fiction, history, and inspirational stories. Podcast Addict. Consumer of Tea. Linux Fanboy. Gamer - Destiny 2. Herbalife devotee. Against #aislop and #bigtech #RejoinEU #BuyFromEU https://european-alternatives.eu/ Coastal dweller of Wirral, UK.
Academic Europe, the leading European career network for Academics, Researchers and Scientists
You've seen all posts