2024-06-08, 13:30–14:15, Track 2 (Moody Rm 101)
LLMs are going to destroy the world but until they do let’s try to understand how they work. The goal of this presentation is to explain to a script kiddie the underlying technologies of how LLMs work. The hope I have for this talk is that understanding LLMs will demystify the buzzwords around AI and help you use this technology in new and innovative ways. -> Please read complete abstract in the notes section.
Large Language Models (LLMs) have changed the world, and they will continue to do so. The impossible job of InfoSec professionals is to understand this emerging technology. LLMs have created a large knowledge gap between InfoSec professionals who understand LLMs and those who don't. The purpose of this talk is to get a basic understanding of the underlying technologies of LLMs, the history of LLMs, and potential future use cases for the technology.
LLMs are systems capable of understanding, generating, and manipulating human-like text. LLMs, such as OpenAI's GPT, are trained on extensive datasets. This training enables them to perform tasks ranging from writing and translation to more sophisticated tasks like coding and problem-solving, without being explicitly programmed for each task. The presentation emphasizes the transformative nature of LLMs in processing natural language, making them a cornerstone of modern AI research.
The historical context of LLMs is addressed, tracing their evolution from simple rule-based models to the sophisticated neural networks we see today. The presentation outlines key milestones in the development of LLMs, including the transition from early models to more complex systems such as the Transformer architecture. This section underscores the rapid advancement in AI and natural language processing (NLP) technologies, highlighting significant breakthroughs that have paved the way for the current generation of LLMs.
Delving into the technical aspects, the presenter explains the underlying technologies that make LLMs possible. This includes an overview of neural networks, focusing on the Transformer architecture. The presentation also covers the training process, including the concept of fine-tuning, which allows LLMs to be adapted to specific tasks with relatively small datasets. The significance of advancements in hardware and algorithms for training and running LLMs.
The presentation then shifts focus to the current applications of LLMs in offensive security. It explores how cybersecurity professionals and ethical hackers are leveraging LLMs for tasks such as generating phishing emails, creating malware, and finding vulnerabilities in software. These use cases demonstrate the dual-edged nature of LLMs, serving both as powerful tools for improving security and as potential vectors for sophisticated cyberattacks.
Looking towards the future, the presenter speculates on how LLMs might further transform offensive security. Potential developments include the creation of more advanced and autonomous cyber-attack mechanisms, the use of LLMs in developing AI-driven offensive security strategies, and the ethical implications of such advancements. This section encourages the audience to consider the broader impacts of LLMs on cybersecurity, highlighting the need for a balanced approach to leveraging AI for security purposes while safeguarding against its misuse.
In conclusion, the presentation provides a detailed overview of the development, capabilities, and impact of LLMs, with a particular focus on their application in offensive security. By examining both the current state and future potential of LLMs, the speaker underscores the importance of ongoing research, ethical considerations, and the development of robust security measures to mitigate the risks associated with these powerful AI tools.
JR Hernandez, a seasoned security professional based in San Antonio, TX, who brings over a decade of experience in cybersecurity. Currently serving as an Offensive Security Manager, JR leads a team of penetration testers at Evolve Security Inc., where he oversees the delivery of offensive security services. His primary responsibility involves ensuring the success of his team by equipping them with the necessary tools, training, and support to excel in their roles.
Beyond his professional endeavors, Jose finds solace in literature, photography, and stand-up comedy, showcasing his diverse interests outside the realm of cybersecurity. With a relentless pursuit of knowledge and a passion for cybersecurity advocacy.