Ask HN: What is the most overlooked risk in the AI security domain? A Hacker News user posting as ToriTech asked the site's community what the most overlooked risk in the AI security domain is, specifically seeking AI/ML or LLM vulnerabilities beyond prompt injection that typical pentesting methods struggle to catch. The Ask HN post, submitted 28 minutes before the page was captured, drew 1 point and asks how pentesters will need to change to find such flaws. | Guidelines newsguidelines.html \| FAQ newsfaq.html \| Lists lists \| API https://github.com/HackerNews/API \| Security security.html \| Legal https://www.ycombinator.com/legal/ \| Apply to YC https://www.ycombinator.com/apply/ \| Contact mailto:hn@ycombinator.com | | | Hacker News news new newest \| past front \| comments newcomments \| ask ask \| show show \| jobs jobs \| submit submit | login login?goto=item%3Fid%3D49669858 | | | | Ask HN: What is the most overlooked risk in the AI security domain? item?id=49669858 | | | | 1 point by ToriTech user?id=ToriTech 28 minutes ago item?id=49669858 \| hide hide?id=49669858&goto=item%3Fid%3D49669858 \| past https://hn.algolia.com/?query=Ask%20HN%3A%20What%20is%20the%20most%20overlooked%20risk%20in%20the%20AI%20security%20domain%3F&type=story&dateRange=all&sort=byDate&storyText=false&prefix&page=0 \| favorite fave?id=49669858&auth=b06334bf417579bc58d5d4c29f32e50f20d49251 \| discuss item?id=49669858 | | | | As someone who's interested in pentesting and red-teaming in general, I'm wondering what are some more dangerous AI/ML or LLM related vulnerabilities besides your usual prompt injection. Specifically, what kinds of flaws are harder to catch with typical pentesting methods, and how do you think pentesters are going to have to change to find them? |