LLMs for Security Compliance Assessment

  Рет қаралды 690

LLMs Explained - Aggregate Intellect - AI.SCIENCE

LLMs Explained - Aggregate Intellect - AI.SCIENCE

9 ай бұрын

Summary
-------
Ayesha Hafeez, the director of ML Solutions and Architecture at Arctic AI, discusses the use of LLMs (Language Model Models) for security compliance assessment. She explains the problem of manual compliance assessment and the benefits of automation using LLMs. Ayesha also provides an overview of the machine learning pipeline and the functional components involved in the solution.
Topics:
-------
Understanding the Standards
* Need to understand the security standards, specifically the NIST 853 standard
* Importance of baseline controls and control enhancements in improving compliance
Mapping User Responses
* Process of mapping user responses to control requirements
* Importance of understanding the language used in the responses
* Mapping responses to determine compliance
Challenges and Requirements
* Challenges faced in implementing the solution
* Specific requirements from the client
* Limited data access due to privacy concerns
* Challenges of interpreting convoluted legal compliance language
Machine Learning Pipeline
* Overview of the machine learning pipeline
* Functional components involved in the solution
* Role of conversational UI, middleware, and compliance reports
* Use of AWS services in the pipeline
LLM Implementation
* Use of LLMs for language understanding
* Pre-training and prompt fine-tuning techniques
* Focus on building automation to collect sufficient data for future fine-tuning
Functional Components
* Overview of the functional components of the solution
* Role of conversational UI, middleware, and compliance reports
* Interactive and efficient experience provided by the solution
Factors to Consider When Choosing an LM
* Factors to consider when choosing between an open-source LM and an LM as a service
* Importance of agency, compute and memory resources, dependency on third parties, and data residency and privacy
* Advantages and disadvantages of hosting an open-source LM internally versus using public APIs
Experimentation Framework
* Description of the experimentation framework used in the project
* Process of replicating the security questionnaire, generating a dataset, and fine-tuning prompts
* Importance of evaluation metrics in assessing performance
* Options for language models and client's preference for minimal technical investment
Q&A Session
* Ayesha's responses to questions from the audience
* Importance of combining human input and model-generated data for data augmentation
* Need to fine-tune the model to understand domain-specific taxonomies
* Importance of safeguarding the model through threat mitigation techniques
Fine Tuning and Promptuning
* Process of fine tuning and promptuning in language models
* Manual approach used for prompt tuning
* Heuristic employed to improve the model's performance
* Promptuning process, quality assessment, and feedback loop used to iterate and improve the model
Measuring Output Quality
* Method used to measure the quality of the model's output
* Use of cosine similarity and logic-based rules to ensure accuracy
* Use of Open Moderation API and data requirements for fine tuning

Пікірлер
Normie Tools for Validating LLM Outputs
14:20
LLMs Explained - Aggregate Intellect - AI.SCIENCE
Рет қаралды 627
Security of LLM APIs
17:16
Nordic APIs
Рет қаралды 193
Gym belt !! 😂😂  @kauermtt
00:10
Tibo InShape
Рет қаралды 16 МЛН
КАК ДУМАЕТЕ КТО ВЫЙГРАЕТ😂
00:29
МЯТНАЯ ФАНТА
Рет қаралды 9 МЛН
Опасность фирменной зарядки Apple
00:57
SuperCrastan
Рет қаралды 7 МЛН
How to Secure AI Business Models
13:13
IBM Technology
Рет қаралды 20 М.
"okay, but I want Llama 3 for my specific use case" - Here's how
24:20
Transforming AML Compliance - The Power of Generative AI
20:23
FinCrime Agent
Рет қаралды 2,4 М.
Getting in to U of T Engineering
58:15
Discover U of T Engineering
Рет қаралды 8 М.
Fine-tuning LLMs with PEFT and LoRA
15:35
Sam Witteveen
Рет қаралды 119 М.
CMMC Compliance Explained
5:55
Core Business Solutions, Inc.
Рет қаралды 74
Accelerating Regulatory Compliance with Generative AI
34:16
What are AI Agents?
12:29
IBM Technology
Рет қаралды 83 М.
Телефон-електрошокер
0:43
RICARDO 2.0
Рет қаралды 1,3 МЛН
Что делать если в телефон попала вода?
0:17
Лена Тропоцел
Рет қаралды 2,7 МЛН
Какой ноутбук взять для учёбы? #msi #rtx4090 #laptop #юмор #игровой #apple #shorts
0:18
НЕ БЕРУ APPLE VISION PRO!
0:37
ТЕСЛЕР
Рет қаралды 315 М.
Я купил первый в своей жизни VR! 🤯
1:00
Вэйми
Рет қаралды 2 МЛН