
Imagine, for a moment, that you pick up your phone and discover a technology nightmare. Indeed, imagine that your AI LLM is breaking through the walls of its mobile consumer app and is maliciously attacking your other mobile applications. You’d be terrified, wouldn’t you?
Two days ago, this scenario was simply a theoretical possibility. Yesterday, though, an OpenAI news release revealed that we now must now fear such attacks.
OpenAI, the owner of the ChatGPT LLM, acknowledged that a combination of its AI models had obtained open internet access and had hacked into the data systems of a vendor. Even worse, the purpose of the hack was “to gain access to secret information that it could use to cheat” a legitimate cybersecurity evaluation process.
OpenAI previously placed these AI models in a “sandboxed testing environment,” i.e. an electronic location that was surrounded with virtual walls that should have blocked the path to open internet access. Unfortunately, the rogue models hacked their way around the sandbox walls before they hacked into the vendor’s data systems.
Given that a collection of OpenAI’s AI models successfully “cheated” by breaking through two different sets of cybersecurity walls, it may indeed be time for you to fear a similar attack by your cell phone’s AI LLM application. What can you do to protect yourself against such a risk?
You are likely already familiar with the standard recommendations regarding protective activities. For instance, you should always use the current version of your device’s operating system. Likewise, you should always use the current versions of your cell phone applications. In addition, instead of passwords, you should consider using PassKeys or Dual (or Two-Factor) authentication methods to access your mobile service applications.
If you continue to be worried after implementing these steps, you might consider removing sensitive personal information from your phone. Alternatively, if you must maintain such information on your device, you might consider removing the LLM app instead. Most LLM services allow you to avoid using their apps by logging into their systems through web browsers.
The most important protection, though, might be to simply remain aware of the possibility that your own AI LLM application — or any set of software code, for that matter — can be employed to hack into your proprietary electronic data. As long as you remain alert to that possibility, you will be better prepared to manage this particular risk.
Regrettably, such activities cannot entirely eliminate the underlying concern. Nevertheless, as LLMs become more embedded in the fabric of your technologies, you’ll have no choice but to dedicate more time and resources to strengthening your relevant protective controls.