
Hacking AI Systems: How to (Still) Trick Artificial Intelligence • Katharine Jarmul • GOTO 2025
Keywords
Summary
168 words
Critical Evaluation
The talk provides a comprehensive overview of adversarial AI/ML, effectively bridging theoretical concepts with practical attack scenarios. Jarmul’s expertise in privacy and security is evident, and she communicates complex ideas in an accessible manner without oversimplifying. The strength of the talk lies in its structured approach: starting with attacker mindset, mapping system architectures, and then systematically identifying vulnerabilities. The use of real-world examples, such as the LAION dataset containing sensitive images, grounds the discussion in concrete issues. However, the talk lacks formal citations to specific research papers, relying instead on general knowledge and the speaker’s experience. While this is acceptable for a conference talk, it limits the ability to verify claims. The discussion of coding theory and embeddings is insightful but could be deepened for a technical audience. The protective measures section is brief, serving as a primer rather than a comprehensive guide. Overall, the talk is valuable for practitioners seeking to understand AI security threats and is well-aligned with its title. The adéquation between title and content is strong, as the talk indeed addresses how to trick AI systems and offers defensive insights.
184 words
Title / Content Match
The title accurately reflects the content, which focuses on adversarial attacks on AI systems and how to protect against them.
Quality & Reliability
8/10
The talk is delivered by a recognized expert in privacy and AI security, with practical examples and references to real-world datasets and research. The content is technically sound and well-structured, though it lacks formal citations and is based on the speaker's experience and general knowledge.
Chapters
Cited Sources
- GOTO Copenhagen 2025 session page — Slides and full abstract of the talk
- Katharine Jarmul's website — Speaker's personal site
- Probably Private — Speaker's company
- Katharine Jarmul's GitHub — Speaker's code repositories
Concurring Sources
- GOTO Copenhagen 2025 session page — Official session description and resources
External References
Contribution & Novelties
The talk provides a practical, attacker-centric perspective on AI security, emphasizing the importance of understanding model weaknesses and the role of training data. It offers a clear framework for analyzing AI systems from a security standpoint, which is valuable for practitioners. The inclusion of real-world examples and resources for further learning enhances its utility.
Pour aller plus loin :
- Adversarial machine learning - Wikipedia — Overview of adversarial attacks and defenses.
- Prompt injection - Wikipedia — Explanation of a key attack vector discussed.
- LAION dataset — Example of a large-scale dataset with potential privacy issues.
95 words
Radar Profile
The radar profile shows high scores in information quantity, quality, and reliability, with a slightly lower technical depth. This indicates a well-balanced talk that is informative and credible, though it may not delve into the most advanced technical details.