Upgrade to Pro — share decks privately, control downloads, hide ads and more …

今だからこそ学ぼう! 生成AIのセキュリティ入門②_公開資料

今だからこそ学ぼう! 生成AIのセキュリティ入門②_公開資料

Nobu Mochizuki

August 26, 2024
Tweet

More Decks by Nobu Mochizuki

Other Decks in Technology

Transcript

  1. ࣸਅࡱӨ ಈըࡱӨ ࢿྉެ։ 4/4֦ࢄ ̋ ̋ ̋ ̋ *#.%PKP ηογϣϯडߨʹ͓͚Δ஫ҙࣄ߲

    ηογϣϯதʹ໎࿭ߦҝ͕ൃ֮ͨ͠৔߹͸ɺڧ੍ୀग़ɺηογϣϯதࢭͳͲͷાஔΛߨ͡·͢
  2. ηΩϡϦςΟʔͷجຊݪଇ ࢀরɿWhat is Cyber Security? https://cyberwaala.medium.com/what-is-cyber-security-ee9241017030 Availability 可用性 ڐՄ͞ΕͨϢʔβʔ͕ɺద੾ͳσʔλʹ ΞΫηεͰ͖ΔΑ͏ʹͳ͍ͬͯΔ͜ͱ

    Integrity 完全性 ڐՄ͞Ε͍ͯͳ͍Ϣʔβʔ͕ɺσʔλʹ ΞΫηε͠վ᜵Ͱ͖ͳ͍Α͏ʹͳ͍ͬͯΔ͜ͱ Confidentiality 機密性 ػີσʔλ΁ͷΞΫηεΛ੍ޚ͠ɺ ݖݶͷͳ͍ୈࡾऀ͕ػີσʔλʹΞΫηε Ͱ͖ͳ͍Α͏੍ݶɺϒϩοΫ͢Δ͜ͱɻ
  3. ࣾ಺ 1$ αʔόʔ Ϋϥ΢υ "1* "1 ΞϓϦ *05 ϦϞʔτϫʔΫ ϞόΠϧ

    "* ϋοΧʔ ϋοΧʔ ϋοΧʔ "*ʹ͓͚ΔσʔλͷྲྀΕ
  4. "*ΞϓϦͷશମ૾ʢ̍ʣɿֶशσʔλͷ४උ ݩσʔλ σʔλ ४උͷ ։ൃ σʔλ४උ༻ͷ ίʔυ ೖྗͱग़ྗ σʔλαϯϓϧ σʔλΤϯδχΞϦϯάɾσʔλαΠΤϯε

    ࢀরɿAttacking and protecting Artificial Intelligence (Event) https://raw.githubusercontent.com/OWASP/www-project-ai-security-and-privacy-guide/main/assets/images/20230215-Rob-AIsecurity-Appsec-ForSharing.pdf ӡ༻σʔλ ӡ༻தίʔυ ։ൃதίʔυ ݕূͱ෼ੳ ӡ༻ɾΨόφϯε
  5. "*ΞϓϦͷશମ૾ʢ̍ʣɿσʔλʹ͓͍ͯϞσϧ։ൃ ݩσʔλ σʔλ ४උͷ ։ൃ σʔλ४උ༻ͷ ίʔυ ೖྗͱग़ྗ σʔλαϯϓϧ σʔλΤϯδχΞϦϯάɾσʔλαΠΤϯε

    ӡ༻σʔλ ӡ༻தίʔυ ։ൃதίʔυ ݕূͱ෼ੳ ӡ༻ɾΨόφϯε ࢀরɿAttacking and protecting Artificial Intelligence (Event) https://raw.githubusercontent.com/OWASP/www-project-ai-security-and-privacy-guide/main/assets/images/20230215-Rob-AIsecurity-Appsec-ForSharing.pdf Ϟσϧ։ൃɾςετ޲͚ͷݕূͱ෼ੳ Ϟσϧֶश ֶशɾςετ༻ ͷίʔυ Ϟσϧͷద༻ ͱֶश͞Εͨ ύλʔϯ "*Ϟσϧ։ൃ
  6. "*ΞϓϦͷશମ૾ʢ̍ʣɿΞϓϦ։ൃɺల։ͱӡ༻ ݩσʔλ σʔλ ४උͷ ։ൃ σʔλ४උ༻ͷ ίʔυ ೖྗͱग़ྗ σʔλαϯϓϧ ΦϖϨʔγϣϯ

    Ψόφϯε ΞϓϦ։ൃ ΞϓϦͷίʔυ ҰൠతͳΞϓϦɾγεςϜ։ൃ ӡ༻ͱΨόφϯε σʔλΤϯδχΞϦϯάɾσʔλαΠΤϯε ӡ༻σʔλ ӡ༻தίʔυ ։ൃதίʔυ ݕূͱ෼ੳ ӡ༻ɾΨόφϯε ࢀরɿAttacking and protecting Artificial Intelligence (Event) https://raw.githubusercontent.com/OWASP/www-project-ai-security-and-privacy-guide/main/assets/images/20230215-Rob-AIsecurity-Appsec-ForSharing.pdf Ϟσϧ։ൃɾςετ޲͚ͷݕূͱ෼ੳ Ϟσϧֶश ֶशɾςετ༻ ͷίʔυ Ϟσϧͷద༻ ͱֶश͞Εͨ ύλʔϯ "*Ϟσϧ։ൃ
  7. γφϦΦͷϑΥʔΧε ݩσʔλ σʔλ ४උͷ ։ൃ σʔλ४උ༻ͷ ίʔυ ೖྗͱग़ྗ σʔλαϯϓϧ ΦϖϨʔγϣϯ

    Ψόφϯε ΞϓϦ։ൃ ΞϓϦͷίʔυ ҰൠతͳΞϓϦɾγεςϜ։ൃ ӡ༻ͱΨόφϯε σʔλΤϯδχΞϦϯάɾσʔλαΠΤϯε ӡ༻σʔλ ӡ༻தίʔυ ։ൃதίʔυ ݕূͱ෼ੳ ӡ༻ɾΨόφϯε ࢀরɿAttacking and protecting Artificial Intelligence (Event) https://raw.githubusercontent.com/OWASP/www-project-ai-security-and-privacy-guide/main/assets/images/20230215-Rob-AIsecurity-Appsec-ForSharing.pdf Ϟσϧ։ൃɾςετ޲͚ͷݕূͱ෼ੳ Ϟσϧֶश ֶशɾςετ༻ ͷίʔυ Ϟσϧͷద༻ ͱֶश͞Εͨ ύλʔϯ "*Ϟσϧ։ൃ ඪ४ΞϓϦɾιϑτ΢ΣΞͷηΩϡϦςΟʔ
  8. ܭը ཁٻఆٛ ͱҊ݅෼ੳ ઃܭ ։ൃɾ࣮૷ ςετ ϦϦʔεɺల ։ อकɺӡ༻ɺ ഇغ

    ιϑτ΢ΣΞ։ൃϥΠϑαΠΫϧͷϨϏϡʔ ࢀরɿγεςϜ։ൃϥΠϑαΠΫϧ IUUQTFOXJLJQFEJBPSHXJLJ4ZTUFNT@EFWFMPQNFOU@MJGF@DZDMF
  9. γφϦΦ̍ͷ՝୊ɿ։ൃͯ͠Δ؀ڥ΁ͷ߈ܸ ஫໨ΤϦΞ ΞϓϦέʔγϣϯ ίʔυ Ϣʔβʔͱ ΤϯυϙΠϯτ ωοτϫʔΫͱ Πϯϑϥ ओͳ՝୊ ͳΓ͢·͠ʢෆਖ਼ΞΫηεʣɾػີσʔλ࿙Ӯɾ

    ཁ݅ఆٛ΍ςετஈ֊ͰηΩϡϦςΟʔ߲໨ͷෆ଍ɾ "1*࿈ܞɾอޢͷϛεͳͲ ίʔυ಺ͷόάʹΑͬͯͷ੬ऑੑɾίʔυϕʔεͷ ҆શੑʢαϓϥΠνΣʔϯ߈ܸʣͳͲ ෆਖ਼ΞΫηεɾਓతϛε΍ѱҙͷ͋ΔΠϯαΠμʔ߈ܸʹ ΑΔσʔλ࿙ӮɾϚϧ΢ΣΞɾϑΟογϯάͳͲ σʔλϕʔεͷෆਖ਼ΞΫηεͱσʔλมߋɾ Πϯϑϥߏ੒ͷෆ۩߹ όοΫΞοϓͷߟྀෆ଍ɾηΩϡϦςΟʔ՝୊ Ϧιʔε΁ͷݖݶ؅ཧͳͲ
  10. ैདྷͷηΩϡϦςΟʔͷϞσϧ ಺෦҆શ ֎෦҆શ͡Όͳ͍ θϩτϥετϞσϧ ಺෦Ͱ͋Ζ͏ͱΞΫηε͸৴༻͠ͳ͍ ձ͕ࣾڐՄ ձ͕ࣾڐՄ ϦϞʔτϫʔΫͷ૿Ճ Ϋϥ΢υαʔϏεͷར༻૿ ಺෦ෆਖ਼ͷ૿Ճ

    ࣾ֎ͱͷަྲྀͷ૿Ճ ࣾ಺֎ͷ*5Πϯϑϥ΍γεςϜΛ؅ཧ͠ͳ͕ΒɺΞΫηεΛ੍ޚ͢Δઓུ ࣾ಺֎໰Θͣ͋ΒΏΔΞΫηεΛ৴༻͠ͳ͍͜ͱΛલఏͱ͢Δ ʮθϩτϥετʯηΩϡϦςΟʔͱ͸ʁ
  11. θϩτϥετɾΞϓϩʔνΛ࢖ͬͨରࡦ ϋΠϒϦουΫϥ΢υͷอޢ r͢΂ͯͷΞΫηεΛ؅ཧɾ ੍ޚ rΫϥ΢υͷΞΫςΟϏςΟʔ ͱߏ੒Λ؂ࢹ r҆શͳΫϥ΢υωΠςΟϒ ϫʔΫϩʔυ ಺෦ڴҖͷϦεΫΛ௿ݮ –

    ϦεΫͷ͋ΔϢʔβʔ׆ಈ Λൃݟ͢Δߴ౓ͳ෼ੳ – ϢʔβʔͷݖݶͱඞཁੑʹԠ͡ ͯσʔλ΁ͷΞΫηεΛ੍ޚ – ڴҖΠϯςϦδΣϯεͷ૊ΈࠐΈ ηΩϡΞͳϦϞʔτϫʔΫ؀ڥ rηΩϡΞͳ#:0%ͱ σόΠε؅ཧ r71/ͷར༻ rύεϫʔυϨεӡ༻
  12. γφϦΦ̍ͷ՝୊ɿओͳରࡦ ஫໨ΤϦΞ ΞϓϦέʔγϣϯ ίʔυ Ϣʔβʔͱ ΤϯυϙΠϯτ ωοτϫʔΫͱ Πϯϑϥ ओͳ՝୊ ΤϯυϢʔβʔෆਖ਼ͷΞΫηεɾػີσʔλ࿙Ӯ

    ηογϣϯϋΠδϟοΫɾ%%04߈ܸ 42-ΠϯδΣΫγϣϯɾ944εΫϦϓτͳͲ ίʔυ಺ͷόάʹΑͬͯͷ੬ऑੑɾίʔυϕʔεͷ ҆શੑʢαϓϥΠνΣʔϯ߈ܸʣͳͲ ෆਖ਼ΞΫηεɾਓతϛε΍ѱҙͷ͋ΔΠϯαΠμʔ߈ܸʹ Αͬͯͷσʔλ࿙ӮɾϚϧ΢ΣΞɾϑΟογϯάͳͲ σʔλϕʔεͷෆਖ਼ΞΫηεͱσʔλมߋɾ.BOJOUIF .JEEMFɾ%%04߈ܸɾΠϯϑϥίϯϑΟάϛε όοΫΞοϓෆ଍ɾΠϯγσϯτ΍ࡂ֐ରࡦෆ଍ εέʔϥϏϦςΟʔɾΞΫηεͱ؀ڥ؅ཧͳͲ ηΩϡϦςΟʔରࡦ ։ൃऀΞΫηε؅ཧɾػີσʔλͷಛఆͱ؅ཧ ೖྗͷύϥϝʔλʔԽͱόϦσʔγϣϯɾग़ྗΤϯίʔσΟϯάͳͲ ηΩϡϦςΟʔͱϓϥΠόγʔΛ૊ΈࠐΜͩ։ൃ࢓૊ɾ ϨϙδτϦʔ؅ཧɾ"1*อޢͳͲ ࠷খݶͷݖݶΛݩʹͨ͠ΞΫηε؅ཧɾଟཁૉೝূ ΤϯυϙΠϯτอޢɾ71/ɾσόΠε؅ཧʢ#:0%ΛؚΉʣ ηΩϡϦςΟʔਓࡐҭ੒ͱσʔλͷར༻໨తͷಁ໌ԽͳͲ σʔλ҉߸ԽͱΞΫηε؅ཧͱ௨৴ͷ҉߸ԽͱωοτϫʔΫ ϞχλϦϯάɾΞηοτͱมߋ؅ཧɾ ϦιʔεͷεέʔϥϏϦςΟʔɾ4-"؅ཧ όοΫΞοϓɾΠϯγσϯτ΍ࡂ֐ͷ෮ڵରࡦɾ؀ڥϞχλϦϯάͳͲ
  13. ࣍ճͷηογϣϯ಺༰ʢʣ ݩσʔλ σʔλ ४උͷ ։ൃ σʔλ४උ༻ͷ ίʔυ ೖྗͱग़ྗ σʔλαϯϓϧ ΦϖϨʔγϣϯ

    Ψόφϯε ΞϓϦ։ൃ ΞϓϦͷίʔυ ҰൠతͳΞϓϦɾγεςϜ։ൃ ӡ༻ͱΨόφϯε σʔλΤϯδχΞϦϯάɾσʔλαΠΤϯε ӡ༻σʔλ ӡ༻தίʔυ ։ൃதίʔυ ݕূͱ෼ੳ ӡ༻ɾΨόφϯε ࢀরɿAttacking and protecting Artificial Intelligence (Event) https://raw.githubusercontent.com/OWASP/www-project-ai-security-and-privacy-guide/main/assets/images/20230215-Rob-AIsecurity-Appsec-ForSharing.pdf Ϟσϧ։ൃɾςετ޲͚ͷݕূͱ෼ੳ Ϟσϧֶश ֶशɾςετ༻ ͷίʔυ Ϟσϧͷద༻ ͱֶश͞Εͨ ύλʔϯ "*Ϟσϧ։ൃ ݩσʔλ σʔλ ४උͷ ։ൃ σʔλ४උ༻ͷ ίʔυ ೖྗͱग़ྗ σʔλαϯϓϧ Ϟσϧ։ൃɾςετ޲͚ͷݕূͱ෼ੳ ΦϖϨʔγϣϯ Ψόφϯε ΞϓϦ։ൃ ΞϓϦͷίʔυ Ϟσϧֶश ֶशɾςετ༻ ͷίʔυ Ϟσϧͷద༻ ͱֶश͞Εͨ ύλʔϯ "*Ϟσϧ։ൃ ҰൠతͳΞϓϦɾγεςϜ։ൃ ӡ༻ͱΨόφϯε σʔλΤϯδχΞϦϯάɾσʔλαΠΤϯε ӡ༻σʔλ ӡ༻தίʔυ ։ൃதίʔυ ݕূͱ෼ੳ ӡ༻ɾΨόφϯε
  14. ϫʔΫγϣοϓɺηογϣϯɺ͓Αͼࢿྉ͸ɺ*#.·ͨ͸ηογϣϯൃදऀʹΑͬͯ४උ͞ΕɺͦΕͧΕಠࣗͷݟղΛ൓өͨ͠΋ͷͰ͢ɻͦΕΒ͸৘ใ ఏڙͷ໨తͷΈͰఏڙ͞Ε͓ͯΓɺ͍͔ͳΔࢀՃऀʹରͯ͠΋๏཯త·ͨ͸ͦͷଞͷࢦಋ΍ॿݴΛҙਤͨ͠΋ͷͰ͸ͳ͘ɺ·ͨ*#.੡඼΍αʔϏε͕͓ ٬༷ʹద༻͋Δಛఆͷ๏ྩʹద߹͢Δ͜ͱΛอূ͢Δ΋ͷͰ΋͋Γ·ͤΜɻຊߨԋࢿྉʹؚ·Ε͍ͯΔ৘ใʹ͍ͭͯ͸ɺ׬શੑͱਖ਼֬ੑΛظ͢ΔΑ͏౒ Ί͓ͯΓ·͕͢ɺʮݱঢ়ͷ··ʯఏڙ͞Εɺ໌ࣔ·ͨ͸໧ࣔʹ͔͔ΘΒͣɺ঎ۀੑɺಛఆͷ໨త΁ͷద߹ੑɺඇ৵֐ੑΛؚΊɺ͍͔ͳΔอূ΋൐Θͳ͍ ΋ͷͱ͠·͢ɻຊߨԋࢿྉ·ͨ͸ͦͷଞͷࢿྉͷ࢖༻ʹΑͬͯɺ͋Δ͍͸ͦͷଞͷؔ࿈ʹΑͬͯɺ͍͔ͳΔଛ֐͕ੜͨ͡৔߹΋ɺ*#.͸੹೚ΛෛΘͳ͍ ΋ͷͱ͠·͢ɻ ຊߨԋࢿྉͰݴٴ͞ΕΔ*#.੡඼ɺϓϩάϥϜɺ·ͨ͸αʔϏε͸ɺ*#.͕ϏδωεΛߦ͍ͬͯΔ͢΂ͯͷࠃɾ஍ҬͰ͝ఏڙՄೳͳΘ͚ Ͱ͸͋Γ·ͤΜɻຊߨԋࢿྉͰݴٴ͞ΕΔকདྷͷల๬ʢ੡඼ϦϦʔε೔෇΍੡඼ػೳΛؚΉʣ͸ɺࢢ৔ػձ·ͨ͸ͦͷଞͷཁҼʹج͍ͮͯ*#.ಠࣗͷܾ ఆݖΛ΋͍ͬͯͭͰ΋มߋͰ͖Δ΋ͷͱ͠ɺকདྷͷ੡඼·ͨ͸ػೳ͕࢖༻ՄೳʹͳΔ͜ͱɺ΋͘͠͸ಛఆͷ݁ՌΛ֬໿͢Δ͜ͱΛҙਤ͢Δ΋ͷͰ͸͋Γ ·ͤΜɻຊߨԋࢿྉ͸ɺݴٴ͞ΕΔ

    *#.੡඼·ͨ͸αʔϏεʹద༻͋Δܖ໿৚݅Λมߋ͢Δ΋ͷͰ΋ɺ௥Ճͷද໌·ͨ͸อূΛҙਤ͢Δ΋ͷͰ΋͋Γ· ͤΜɻ ຊߨԋࢿྉʹؚ·Ε͍ͯΔ಺༰͸ɺࢀՃऀͷ׆ಈʹΑͬͯಛఆͷ݁Ռ͕ੜ͡Δͱड़΂Δɺ·ͨ͸҉ࣔ͢Δ͜ͱΛҙਤͨ͠΋ͷͰ΋ɺ·ͨͦͷΑ͏ͳ݁Ռ ΛੜΉ΋ͷͰ΋͋Γ·ͤΜɻ ύϑΥʔϚϯε͸ɺ؅ཧ͞Εͨ؀ڥʹ͓͍ͯඪ४తͳ*#.ϕϯνϚʔΫΛ࢖༻ͨ͠ଌఆͱ༧ଌʹج͍͍ͮͯ·͢ɻϢʔβʔ ͕ܦݧ͢Δ࣮ࡍͷεϧʔϓοτ΍ύϑΥʔϚϯε͸ɺϢʔβʔͷδϣϒɾετϦʔϜʹ͓͚ΔϚϧνϓϩάϥϛϯάͷྔɺೖग़ྗߏ੒ɺετϨʔδߏ੒ɺ ͓Αͼॲཧ͞ΕΔϫʔΫϩʔυͳͲͷߟྀࣄ߲ΛؚΉɺ਺ଟ͘ͷཁҼʹԠͯ͡มԽ͠·͢ɻ͕ͨͬͯ͠ɺݸʑͷϢʔβʔ͕͜͜Ͱड़΂ΒΕ͍ͯΔ΋ͷͱ ಉ༷ͷ݁ՌΛಘΒΕΔͱ֬໿͢Δ΋ͷͰ͸͋Γ·ͤΜɻهड़͞Ε͍ͯΔ͢΂ͯͷ͓٬༷ࣄྫ͸ɺͦΕΒͷ͓٬༷͕ͲͷΑ͏ʹ*#.੡඼Λ࢖༻͔ͨ͠ɺ· ͨͦΕΒͷ͓٬༷͕ୡ੒ͨ݁͠Ռͷ࣮ྫͱͯࣔ͠͞Εͨ΋ͷͰ͢ɻ࣮ࡍͷ؀ڥίετ͓ΑͼύϑΥʔϚϯεಛੑ͸ɺ͓٬༷͝ͱʹҟͳΔ৔߹͕͋Γ·͢ɻ • *#.ɺ*#.ϩΰɺJCNDPNɺ watsonx.aiä͸ɺ ੈքͷଟ͘ͷࠃͰొ࿥͞Εͨ*OUFSOBUJPOBM#VTJOFTT.BDIJOFT$PSQPSBUJPOͷ঎ඪͰ͢ɻଞͷ੡඼໊ ͓ΑͼαʔϏε໊౳͸ɺͦΕͧΕ*#.·ͨ͸֤ࣾͷ঎ඪͰ͋Δ৔߹͕͋Γ·͢ɻݱ࣌఺Ͱͷ *#.ͷ঎ඪϦετʹ͍ͭͯ͸ɺ XXXJCNDPNMFHBMDPQZUSBEFTIUNMΛ͝ཡ͍ͩ͘͞ɻ