مدلهای زبانی بزرگ (Large Language Models یا LLMs) نه تنها مسیر هوش مصنوعی را شکل میدهند، بلکه عصر جدیدی از چالشهای امنیتی را نیز نمایان کردهاند. این کتاب کاربردی مستقیماً به قلب این تهدیدات میپردازد. استیو ویلسون، مدیر ارشد محصول در Exabeam، منحصراً بر روی LLMها تمرکز کرده و از مباحث عمومی امنیت هوش مصنوعی پرهیز میکند تا به ویژگیها و آسیبپذیریهای منحصربهفرد ذاتی این مدلها بپردازد. این راهنما با بهرهگیری از خرد جمعی حاصل از ایجاد لیست OWASP Top 10 برای LLMها—که دستاوردی با مشارکت بیش از ۴۰۰ متخصص صنعت است—راهنماییهای دنیای واقعی و استراتژیهای عملی را برای کمک به توسعهدهندگان و تیمهای امنیتی ارائه میدهد تا با واقعیتهای برنامههای کاربردی مبتنی بر LLM دستوپنج نرم کنند. چه در حال معماری یک برنامه جدید باشید و چه در حال افزودن ویژگیهای هوش مصنوعی به یک برنامه موجود، این کتاب منبع اصلی شما برای تسلط بر چشمانداز امنیتی در مرز بعدی هوش مصنوعی است.
اشتراکی

با مرور فصلها، ساختار ، محتوای کتاب را به سرعت بشناسید.
با مرور فصلهای این کتاب میتونی خیلی سریع بفهمی هر بخش چی یاد میده، ساختار کلی چطوره و از کجا باید شروع کنی. هر فصل روی یک مفهوم یا مهارت خاص تمرکز داره و موضوعات اصلیش رو میبینی تا انتخابت آگاهانهتر باشه. چه بخوای کل کتاب رو دنبال کنی، چه فقط یک بخش خاص رو دنبال کنی، این نما کمکت میکنه مسیرت رو پیدا کنی.

چتباتهایی که بدرفتار میشوند
Let’s Talk About Tay • Tay’s Rapid Decline • Why Did Tay Break Bad? • It’s a Hard Problem
درحال تولید...

ده مورد برتر OWASP برای برنامههای کاربردی LLM
About OWASP • The Top 10 for LLM Applications Project • Project Execution • Reception • Keys to Success • This Book and the Top 10 List
درحال تولید...

معماریها و مرزهای اعتماد
AI, Neural Networks, and Large Language Models: What’s the Difference? • The Transformer Revolution: Origins, Impact, and the LLM Connection • Origins of the Transformer • Transformer Architecture’s Impact on AI • Types of LLM-Based Applications • LLM Application Architecture • Trust Boundaries • The Model • User Interaction • Training Data • Access to Live External Data Sources • Access to Internal Services • Conclusion
درحال تولید...

تزریق پرامپت
Examples of Prompt Injection Attacks • Forceful Suggestion • Reverse Psychology • Misdirection • Universal and Automated Adversarial Prompting • The Impacts of Prompt Injection • Direct Versus Indirect Prompt Injection • Direct Prompt Injection • Indirect Prompt Injection • Key Differences • Mitigating Prompt Injection • Rate Limiting • Rule-Based Input Filtering • Filtering with a Special-Purpose LLM • Adding Prompt Structure • Adversarial Training • Pessimistic Trust Boundary Definition • Conclusion
درحال تولید...

آیا مدل زبانی شما بیش از حد میداند؟
Real-World Examples • Lee Luda • GitHub Copilot and OpenAI’s Codex • Knowledge Acquisition Methods • Model Training • Foundation Model Training • Security Considerations for Foundation Models • Model Fine-Tuning • Training Risks • Retrieval-Augmented Generation • Direct Web Access • Accessing a Database • Learning from User Interaction • Conclusion
درحال تولید...

آیا مدلهای زبانی خواب گوسفندان برقی را میبینند؟
Why Do LLMs Hallucinate? • Types of Hallucinations • Examples • Imaginary Legal Precedents • Airline Chatbot Lawsuit • Unintentional Character Assassination • Open Source Package Hallucinations • Who’s Responsible? • Mitigation Best Practices • Expanded Domain-Specific Knowledge • Chain of Thought Prompting for Increased Accuracy • Feedback Loops: The Power of User Input in Mitigating Risks • Clear Communication of Intended Use and Limitations • User Education: Empowering Users Through Knowledge • Conclusion
درحال تولید...

به هیچکس اعتماد نکن
Zero Trust Decoded • Why Be So Paranoid? • Implementing a Zero Trust Architecture for Your LLM • Watch for Excessive Agency • Securing Your Output Handling • Building Your Output Filter • Looking for PII with Regex • Evaluating for Toxicity • Linking Your Filters to Your LLM • Sanitize for Safety • Conclusion
درحال تولید...

کیف پول خود را گم نکنید
DoS Attacks • Volume-Based Attacks • Protocol Attacks • Application Layer Attacks • An Epic DoS Attack: Dyn • Model DoS Attacks Targeting LLMs • Scarce Resource Attacks • Context Window Exhaustion • Unpredictable User Input • DoW Attacks • Model Cloning • Mitigation Strategies • Domain-Specific Guardrails • Input Validation and Sanitization • Robust Rate Limiting • Resource Use Capping • Monitoring and Alerts • Financial Thresholds and Alerts • Conclusion
درحال تولید...

ضعیفترین حلقه را پیدا کنید
Supply Chain Basics • Software Supply Chain Security • The Equifax Breach • The SolarWinds Hack • The Log4Shell Vulnerability • Understanding the LLM Supply Chain • Open Source Model Risk • Training Data Poisoning • Accidentally Unsafe Training Data • Unsafe Plug-ins • Creating Artifacts to Track Your Supply Chain • Importance of SBOMs • Model Cards • Model Cards Versus SBOMs • CycloneDX: The SBOM Standard • The Rise of the ML-BOM • Building a Sample ML-BOM • The Future of LLM Supply Chain Security • Digital Signing and Watermarking • Vulnerability Classifications and Databases • Conclusion
درحال تولید...

درس گرفتن از تاریخ آینده
Reviewing the OWASP Top 10 for LLM Apps • Case Studies • Independence Day: A Celebrated Security Disaster • 2001: A Space Odyssey of Security Flaws • Conclusion
درحال تولید...

به فرآیند اعتماد کنید
The Evolution of DevSecOps • MLOps • LLMOps • Building Security into LLMOps • Security in the LLM Development Process • Securing Your CI/CD • LLM-Specific Security Testing Tools • Managing Your Supply Chain • Protect Your App with Guardrails • The Role of Guardrails in an LLM Security Strategy • Open Source Versus Commercial Guardrail Solutions • Mixing Custom and Packaged Guardrails • Monitoring Your App • Logging Every Prompt and Response • Centralized Log and Event Management • User and Entity Behavior Analytics • Build Your AI Red Team • Advantages of AI Red Teaming • Red Teams Versus Pen Tests • Tools and Approaches • Continuous Improvement • Establishing and Tuning Guardrails • Managing Data Access and Quality • Leveraging RLHF for Alignment and Security • Conclusion
درحال تولید...

چارچوبی کاربردی برای امنیت مسئولانه هوش مصنوعی
Power • GPUs • Cloud • Open Source • Multimodal • Autonomous Agents • Responsibility • The RAISE Framework • The RAISE Checklist • Conclusion
درحال تولید...
12 فصل در حال تولید
مدت زمان خوانش
6:4
نوع کتاب
اشتراکی
شرکت کنندگان
0 نفر
تولید کتاب
۳۱ شهریور ۱۴۰۵