Enterprise

HiddenLayer emerges from stealth to protect AI models from attacks

Comment

Abstract glowing grid and particles
Image Credits: piranka / Getty Images

As AI-powered services like OpenAI’s GPT-3 grow in popularity, they become an increasingly attractive attack vector. Even shielded behind an API, hackers can attempt to reverse-engineer the models underpinning these services or use “adversarial” data to tamper with them. According to Gartner, 30% of all AI cyberattacks in 2022 will leverage these techniques along with data poisoning, which involves injecting bad data into the dataset used to train models to attack AI systems.

As in any industry, fighting security threats is a never-ending task. But Chris Sestito claims that his platform, HiddenLayer, can simplify it for AI-as-a-service vendors by automatically identifying malicious activity against models and responding to attacks.

HiddenLayer today emerged from stealth with $6 million in seed funding from Ten Eleven Ventures, Secure Octane and other investors. Sestito, the former director of threat research at Cylance and VP of engineering at Qualys, co-founded the company several months ago with Tanner Burns and Jim Ballard. Burns and Ballard also worked at Qualys and Cylance and spent time together at BlackBerry, where Ballard was a data curation team lead and Burns was a threat researcher.

“Virtually all enterprise organizations have made significant resource contributions to machine learning to give themselves an advantage — whether that value is in the form of product differentiation, revenue generation, cost savings or efficiencies,” Sestito told TechCrunch in an email interview. “Adversarial machine learning attacks are capable of causing all of the same damage we’ve seen in traditional cyber attacks including exposing customer data and destroying production systems. In fact, at HiddenLayer, we believe we’re not far off from seeing machine learning models ransomed back to their organizations.”

HiddenLayer claims that its technology can defend models from attacks without the need to access any raw data or a vendor’s algorithms. By analyzing model interactions — in other words, the data fed into the model (e.g., a picture of cats) and the predictions that the model outputs (e.g., the caption “cats”) — to spot patterns that could be malicious, HiddenLayer can work “non-invasively” and without prior knowledge of training data, Sestito said.

“Adversarial machine learning attacks are not loud like ransomware — you have to be looking for them to catch them in time,” Sestito said. “HiddenLayer has focused on a research-first approach that will allow us to publish our findings and train the world to be prepared.”

Mike Cook, an AI researcher who’s a part of the Knives and Paintbrushes collective, said that it’s unclear whether HiddenLayer is doing anything “truly groundbreaking or new.” (Cook is unaffiliated with HiddenLayer.) Still, he notes that there’s a benefit to what HiddenLayer appears to be doing: trying to package up knowledge about attacks on AI and make them more widely accessible.

“The AI boom is still booming, but a lot of that knowledge about how modern machine learning works and how best to use it is still locked away mostly to people who have specialist knowledge. Memorable examples for me include researchers managing to extract individual pieces of training data from OpenAI’s GPT-2 and GPT-3 systems,” Cook told TechCrunch via email. “When expert knowledge is inaccessible and hard to come by, sometimes all a business really needs is to provide convenient ways to get at it.”

HiddenLayer is currently pre-revenue and doesn’t have customers, although Sestito says that the startup has engaged several “high-profile” design partners. Ultimately, Cook believes its success will depend less on HiddenLayer’s technology and more on whether the threat from attacks is as great as the company claims.

“I don’t know how prevalent attacks on machine learning systems are [at present]. Tricking a spam filter into letting through an email is very different in scale and severity to extracting proprietary data from a large language model,” Cook said.

To his point, it’s difficult to pin down real-world examples of attacks against AI systems. Research into the topic has exploded, with more than 1,500 papers on AI security published in 2019 on the scientific publishing site Arxiv.org, up from 56 in 2016, according to a study from Adversara. But there’s little public reporting on attempts by hackers to, for example, attack commercial facial recognition systems — assuming such attempts are happening in the first place.

Sestito asserts the threat — regardless of its size today — will grow with the AI market, implicitly to the advantage of HiddenLayer. He acknowledges that several startups already offer products designed to make AI systems more robust, including Robust Intelligence, CalypsoAI and Troj.ai. But Sestito claims that HiddenLayer stands alone in its AI-driven detection and response approach.

“PwC believes that AI will be a $15.7 trillion dollar market by 2030. We absolutely have to start defending this technology now,” Sestito said. “Our biggest goal by far is educating the market on this new threat. The commitment to AI and machine learning is relatively new to many organizations and few have been focusing on defending those assets. With any new technology comes new attack vectors; this is the same fight on a new frontier.”

Austin, Texas-based HiddenLayer currently has 11 employees and expects to finish 2022 with 14.

More TechCrunch

In addition to the federal funding, the state of New Mexico — where SolAero is based — committed to providing financing and incentives that value $25.5 million.

Biden administration looks to give Rocket Lab $24M to boost space-grade solar cell production

Some of the new Apple Intelligence features that Apple debuted at WWDC 2024 don’t even feel like AI, they just feel like smarter tools. 

Apple’s AI, Apple Intelligence, is boring and practical — that’s why it works

The TechCrunch team runs down all of the biggest news from the Apple WWDC 2024 keynote in an easy-to-skim digest.

Here’s everything Apple announced at the WWDC 2024 keynote, including Apple Intelligence, Siri makeover

Jordan Meyer and Mathew Dryhurst founded Spawning AI to create tools that help artists exert more control over how their works are used online. Their latest project, called Source.Plus, is…

Spawning wants to build more ethical AI training datasets

After leading the social media landscape, TikTok appears to be interested in challenging Google’s dominance in search. The company confirmed to TechCrunch that it’s testing the ability for users to…

TikTok comes for Google as it quietly rolls out image search capabilities in TikTok Shop

General Motors is investing $850 million into Cruise as the autonomous vehicle subsidiary slowly makes its way back to testing in Phoenix, Dallas and, as of Tuesday, Houston. GM’s CFO…

GM gives Cruise $850M lifeline as it relaunches robotaxis in Houston

These messaging features, announced at WWDC 2024, will have a significant impact on how people communicate every day.

At last, Apple’s Messages app will support RCS and scheduling texts

Welcome to TechCrunch Fintech! This week, we’re looking at Rippling’s controversial decision to ban some former employees from selling their stock, Carta’s massive valuation drop, a GenZ-focused fintech raise, and…

Rippling’s tender offer decision draws mixed — and strong — reactions

Google is finally making its Gemini Nano AI model available to Pixel 8 and 8a users after teasing it in March.

Google’s June Pixel feature drop brings Gemini Nano AI model to Pixel 8 and 8a users

At WWDC 2024, Apple introduced new options for developers to promote their apps and earn more from them in the App Store.

Apple adds win-back subscription offers and improved search suggestions to the App Store

iOS 18 will be available in the fall as a free software update.

Here are all the devices compatible with iOS 18

The acquisition comes as BeReal was struggling to grow its user base and was looking for a buyer.

BeReal is being acquired by mobile apps and games company Voodoo for €500M

Unlike Light’s older phones, the Light III sports a larger OLED display and an NFC chip to make way for future payment tools, as well as a camera.

Light introduces its latest minimalist phone, now with an OLED screen but still no addictive apps

Since April, a hacker with a history of selling stolen data has claimed a data breach of billions of records — impacting at least 300 million people — from a…

The mystery of an alleged data broker’s data breach

Diversity Spotlight is a feature on Crunchbase that lets companies add tags to their profiles to label themselves.

Crunchbase expands its diversity-tracking feature to Europe

Thanks to Apple’s newfound — and heavy — investment in generative AI tech, the company had loads to showcase on the AI front, from an upgraded Siri to AI-generated emoji.

The top AI features Apple announced at WWDC 2024

A Finnish startup called Flow Computing is making one of the wildest claims ever heard in silicon engineering: by adding its proprietary companion chip, any CPU can instantly double its…

Flow claims it can 100x any CPU’s power with its companion chip and some elbow grease

Five years ago, Day One Ventures had $11 million under management, and Bucher and her team have grown that to just over $450 million.

The VC queen of portfolio PR, Masha Bucher, has raised her largest fund yet: $150M

Particle announced it has partnered with news organization Reuters to collaborate on new business models and experiments in monetization.

AI news reader Particle adds publishing partners and $10.9M in new funding

Mistral AI has closed its much-rumored Series B funding round, raising €600 million (around $640 million) in a mix of equity and debt.

Paris-based AI startup Mistral AI raises $640M

Cognigy is helping create AI that can handle the highly repetitive, rote processes center workers face daily.

Cognigy lands cash to grow its contact center automation business

ChatGPT, OpenAI’s text-generating AI chatbot, has taken the world by storm. What started as a tool to hyper-charge productivity through writing essays and code with short text prompts has evolved…

ChatGPT: Everything you need to know about the AI-powered chatbot

Featured Article

Raspberry Pi is now a public company

Raspberry Pi priced its IPO on the London Stock Exchange on Tuesday morning at £2.80 per share, valuing it at £542 million, or $690 million at today’s exchange rate.

11 hours ago
Raspberry Pi is now a public company

Hello and welcome back to TechCrunch Space. What a week! In the same seven-day period, we watched Boeing’s Starliner launch astronauts to space for the first time, and then we…

TechCrunch Space: A week that will go down in history

Elon Musk’s posts seem to misunderstand the relationship Apple announced with OpenAI at WWDC 2024.

Elon Musk threatens to ban Apple devices from his companies over Apple’s ChatGPT integrations

“We’re looking forward to doing integrations with other models, including Google Gemini, for instance, in the future,” Federighi said during WWDC 2024.

Apple confirms plans to work with Google’s Gemini ‘in the future’

When Urvashi Barooah applied to MBA programs in 2015, she focused her applications around her dream of becoming a venture capitalist. She got rejected from every school, and was told…

How Urvashi Barooah broke into venture after everyone told her she couldn’t

Slack CEO Denise Dresser is speaking at TechCrunch Disrupt 2024.

Slack CEO Denise Dresser is coming to TechCrunch Disrupt this October

Apple kicked off its weeklong Worldwide Developers Conference (WWDC 2024) event today with the customary keynote at 1 p.m. ET/10 a.m. PT. The presentation focused on the company’s software offerings…

Watch the Apple Intelligence reveal, and the rest of WWDC 2024 right here

Apple’s SDKs (software development kits) have been updated with a variety of new APIs and frameworks.

Apple brings its GenAI ‘Apple Intelligence’ to developers, will let Siri control apps