Employees are feeding sensitive data to ChatGPT, raising security fears
1–10 of 355 posts
Re: Employees are feeding sensitive data to ChatGPT, raising security fears
#2Re: Employees are feeding sensitive data to ChatGPT, raising security fears
#3Re: Employees are feeding sensitive data to ChatGPT, raising security fears
#4While this is not a new problem -- employees share sensitive data with Google all the time -- the data leakage will be more clear than ever. With ads-based tracking and Google search, the leakage was very indirect. With generative AI, it can literally regurgitate memorized documents.
The security risk goes beyond data exfiltration. Folks are already trying to teach the AI incorrect information by spamming it with something like 2+2 = 5.
Data exfiltration + incorrect data injection are super underrated risks to mass adoption of generative AI tech in the B2B world...
Re: Employees are feeding sensitive data to ChatGPT, raising security fears
#5- there’s no way they’re manually scrubbing out sensitive data so its bound to spill out from the training data when prompting the model
- OpenAI is openly storing all this data they’re collecting to the extent that they’ve had several leaks now where people can see others’ conversations and data. We are one step away if it hasn’t already happened from an exploit of their systems (that likely weren’t built with security as the top priority as opposed to scale and performance) that could leak a monumental amount of data from users.
In the most innocent case they could leak the personal info of naive users. But largely if Linkedin is any indication, the business world is filled with dopes who genuinely believe the AI is free thinking and better than their employees. For every org that restricts ChatGPT use, there are fifty others that don’t, most of which have at least one of said dopes who are ready to upload confidential data at a moments notice.
Wouldn’t even put it past military personnel putting S/TS information into it at this point. OpenAI should include more brazen warnings against providing this type of data if they want to keep up this facade of “we can’t release it because ethics” because cybersecurity is a much more real liability than a supervised LM turning into terminator.
Re: Employees are feeding sensitive data to ChatGPT, raising security fears
#6Re: Employees are feeding sensitive data to ChatGPT, raising security fears
#7Which is why a private option is so critical. To not fight against human nature, means providing an ability to use the tool in a safe way.
Re: Employees are feeding sensitive data to ChatGPT, raising security fears
#8Wouldn't it be trivial to add a "read-only" mode to the LLM's operation, where it uses stored knowledge to answer queries but doesn't ingest new knowledge from those queries?
> You can request to opt out of having your content used to improve our services at any time by filling out this form (https://docs.google.com/forms/d/1t2y-arKhcjlKc1I5ohl9Gb16t6S...). This opt out will apply on a going-forward basis only.
It goes to a google form, which is I guess better then them building their own survey platform from scratch that may have more vulnerabilities.
Re: Employees are feeding sensitive data to ChatGPT, raising security fears
#9Re: Employees are feeding sensitive data to ChatGPT, raising security fears
#10Hahahahahahaha