Personal Portfolio for Zi Han Ding
My name is Zi Han Ding and I am a MS CS graduate from the University of Pittsburgh. My primary interests are in applied security research, right now, I am particularly interested in Large Language Models (LLMs) and their related impacts in security.
In the rapidly evolving landscape of LLM applications in almost every imaginable field from academia to industry, security is being ignored. Part of the reason is that security for LLM is a difficult problem to tackle. We cannot simply restrict LLM’s access to data. An LLM with limited access will have limited utility. We also cannot give it complete control over our information. An LLM with complete access is just inviting any attackers of any level to have a go at exfiltrating your private and often personal data. Applied security scientists and engineers must now tackle this the hard way. Understanding what the underlying architecture of the LLM is and how to prevent specific information from leaking.
From a technical perspective, this is challenging. The LLM is a supersized blackbox with trillions and trillions of parameters that cannot be analyzed. We don’t know what it means for this neuron to have a weight of x and a bias of y and we certainly don’t know how to stop it from completing the prompt with someone’s banking information. This means applied security scientists and engineers needs to dive into explainable AI, NLP, deep learning, etc. Coming up with solutions that are vague, incomplete and not guaranteed to work.
From a security perspective, one might suggest to simply put stricter controls until the time is right. Unfortunately, we are past that point now. There is no way to un-unleash the beast that is LLMs. People will find ways to get around the strict controls outside of our jurisdiction, with data that is meant to be secured.
Anyways, apart from this rather grim outlook on LLMs and applied security, this is Zi Han Ding and welcome to my personal website.
