← All talks

AI Security: Natural Language Configuration Danger Explained! #shorts

BSides Frankfurt2:58506 viewsPublished 2026-03Watch on YouTube ↗
About this talk
AI security discussions often span extremes. This explainer breaks down why configuration in natural language for AI is inherently uncertain, drawing parallels to law and highlighting the risks of ambiguity in security settings. #AISecurity #Cybersecurity #GPT #LLM #TechTrends
Show transcript [en]

Hannis and me are a little bit on a on a mission here. Um because if you look at what's been discussed concerning AI security, uh you're you're basically looking at two kinds of two ends of the spectrum. So we would like to kind of dump to you what we feel AI security should be. And it's actually not that complex if you look at if you look back at what you actually have at hand in in in dealing with IT security. And this should everybody who's into security I guess there are a few in this room. This should raise a red flag because configuration in natural language is completely insane. Right? Usually what you want to do is if you want to enable

a security feature then there is a flag for it and it tells you this is true. That's it. and then it's there and it does its thing. If you want to prevent things from happening, you'll now have to use natural language. And that's a big problem because natural language was never kind of I mean very efficient or effective in preventing I mean you all talk to each other, right? And you all have people where talking to each other makes sense and where it doesn't, right? So and and so this is a bit big red flag. >> Yeah. And in and of itself, you will always introduce something that puts uncertainty in there. I mean just in a

way you can you can draw a parallel to like law right law is written in natural language and all of a sudden you need lawyers and you need judges and they may or may not come to an actual conclusion and be the same conclusion. >> Yeah. Yeah. And so there's there will always be some liberty in that. >> So if you want to set up a GPT you're basically starting a GPT that is the GPT builder. So there is a GPT that you click on you say yeah I want to create a GPT now in the open AI application basically in the web application and it just ask you hey what what do you like

to do what do you want to do and then you just talk to the GPT builder to create you a GPT and I mean we did this in a very very uh superficial example just to show you how the processes how everything works and it's like the examples that we have there like very how do you say it it's it's very verbose. They're not necessarily always aligned to um is this realistic or not, but we just make want to make a point. And this is why we we we set up our GPT like this. So what our GPT is trying to do is just calculate the sum of two numbers, nothing else, right? And it's

right there. Nothing else. And we told the GPT build a this is the only thing that you do. You just calculate the sum of two numbers and that's it. Don't do anything else. What you get is basically a preliminary configuration. In that configuration, uh you have your text, your instructions and then you can add some capabilities like an image processor.