In the following sections, we will go through some world-states that hopefully paint a little bit of a clearer picture of risks when it comes to AI. Although the sections have been divided into misuse, misalignment, and systemic, it is important to remember that this is for the sake of explanation. It is highly likely that the future will involve a mix of risks emerging from all of these categories.
Technology increases the harm impact radius. Technology is an amplifier of intentions. As it improves, so does the radius of its effects. Think about the harm that a person could do when utilizing other tools throughout history. During the Stone Age, with a rock, maybe someone could harm ~5 people; a few hundred years ago, with a bomb, someone could harm ~100 people. In 1945, with a nuclear weapon, one person could harm ~250,000 people. If we experience a nuclear winter today, the harm radius would be almost 5 billion people, which is ~60% of humanity. If we assume that transformative AI is a tool that overshadows the power of all others that came before it, then a single person misusing this could have a blast radius that potentially harms 100% of humanity (Munk Debate, 2023).
If many people have access to tools that can be both highly beneficial or catastrophically harmful, then it might only take one single person to cause significant devastation to society. So the growing potential for AIs to empower malicious actors may be one of the most severe threats humanity will face in the coming decades.
Bio Risk #
When we look at ways AI could enable harm through misuse, one of the most concerning cases involves biology. Just as AI can help scientists develop new medicines and understand diseases, it can also make it easier for bad actors to create biological weapons.
AI-enabled bioweapons represent a qualitatively different threat class due to their self-replicating nature and asymmetric cost structure. Unlike conventional weapons with localized effects, engineered pathogens can self-replicate and spread globally. The COVID-19 pandemic demonstrated how even relatively mild viruses can cause widespread harm despite safeguards (Pannu et al., 2024). The offense-defense balance in biotechnology development compounds these risks - developing a new virus might cost around 100 thousand dollars, while creating a vaccine against it could cost over 1 billion dollars (Mouton et al., 2023).
Several different types of AI models could enable biological threats with different risk profiles. Foundation models like LLMs primarily lower knowledge barriers by providing research assistance, protocol guidance, and troubleshooting advice across the entire bioweapon development pipeline. In contrast, specialized biological design tools similar to AlphaFold, AlphaProteo or viral and bacterial design systems could enable fundamentally new capabilities - designing novel pathogens with specific properties, optimizing virulence or transmission characteristics, or creating agents that evade existing countermeasures (Sandbrink, 2023).
Empirical studies demonstrate AI-enabled biorisks. Researchers took an AI model designed for drug discovery and redirected it by rewarding toxicity instead of therapeutic benefit. This led the model to produce 40,000 potentially toxic molecules within six hours, some more deadly than known chemical weapons (Urbina et al., 2022). Demonstrations have shown that students with no biology background were able to use AI chatbots to rapidly gather sensitive information - "within an hour, they identified potential pandemic pathogens, methods to produce them, DNA synthesis firms likely to overlook screening, and detailed protocols" (Soice et al., 2023). 2
When compared to the baseline of having internet access (being able to look up information online), it was concluded by the US National Security Commission on emerging biotechnology that AI models do not meaningfully increase bioweapon risks beyond existing information sources as of late 2024 (Mouton et al., 2023; Peppin et al., 2024; NSCEB, 2024). However, it is very important to keep in mind that capturing a snapshot of 2023 era level capabilities is not indicative of the risks we might need to prepare for in the future. For example, 46 biosecurity and biology experts predicted AI wouldn't match top virology teams on troubleshooting tasks until after 2030, but subsequent testing found this threshold had already been crossed (Williams et al., 2025). This pattern suggests that even domain experts consistently underestimate the pace of AI progress in their own fields, potentially leaving insufficient time for adequate safety preparations. It is also worth noting that biorisk benchmarks often fail to capture many real-world complexities, making it hard to be certain what this saturation implies for biorisk (Ho & Berg, 2025).
Broader technological trends combined with AI could help overcome barriers. Creating biological weapons still requires extensive practical expertise and resources. Experts estimate that in 2022, about 30,000 individuals worldwide possessed the skills needed to follow even basic virus assembly protocols (Esvelt, 2022). Key barriers include specialized laboratory skills, tacit knowledge, access to controlled materials and equipment, and complex testing requirements (Carter et al., 2023). However, DNA synthesis costs have been halving every 15 months (Carlson, 2009). Automated "cloud laboratories" allow researchers to remotely conduct experiments by sending instructions to robotic systems. Benchtop DNA synthesis machines (at-home devices that can print custom DNA sequences) are also becoming more widely available. Combined with increasingly sophisticated AI assistance for experimental design and optimization, these developments could make creating custom biological agents more accessible to people without extensive resources or institutional backing (Carter et al., 2023).
Example: A 2023 MIT study exposed significant vulnerabilities in DNA synthesis screening. Beyond bioagent design, there are significant vulnerabilities in the DNA synthesis screening pipeline. During a 2023 MIT study, researchers were successfully able to order fragments of the 1918 pandemic influenza virus and ricin toxin by employing simple evasion techniques like splitting orders across companies and camouflaging sequences with unrelated genetic code. Nearly all vendors fulfilled these disguised orders, including 12 of 13 members of the International Gene Synthesis Consortium (IGSC), which represents about 80% of commercial DNA synthesis capacity (The Bulletin, 2024).
Cyber Risk #
Even without AI, the global cybersecurity infrastructure shows vulnerabilities. A single software update by CrowdStrike caused airlines to stop flights, hospitals to cancel surgeries, and banks to stop processing transactions causing over 5 billion dollars of damage (CrowdStrike, 2024). This wasn't even a cyber attack - it was an accident. In deliberate attacks, we have examples like the colonial pipeline ransomware attack which caused widespread gas shortages (CISA, 2021; Cunha & Estima, 2023), or the Sony Pictures hack through targeted phishing emails by North Korea (Slattery et al., 2024). These are just a couple of examples amongst many others. It shows how vulnerable our computer systems are, and why we need to think carefully about how AI could make attacks worse.
The global cyber infrastructure has cyberattack overhangs. Beyond accidents and demonstrated attacks, we also face "cyberattack overhangs" - where devastating attacks are possible but haven't occurred due to attacker restraint rather than robust defenses. As an example, Chinese state actors are claimed to have already positioned themselves inside critical U.S. infrastructure systems (CISA, 2024). This type of cyber deterrent positioning can happen between any group of nations. Due to such cyber attack overhangs several actors might have the potential capability to disrupt water controls, energy systems, and ports in different nations. The point we are trying to illustrate is that as far as cyber security is concerned, society is in a pretty precarious state, even before AI comes into the picture.
AI enables automated, highly personalized phishing at scale. AI-generated phishing emails achieve higher success rates (65% vs 60% for human-written) while taking 40% less time to create (Slattery et al., 2024). Tools like FraudGPT automate this customization using targets' background, interests, and relationships. Adding to this threat, open source AI voice cloning tools just minutes of audio to create convincing replicas of someone's voice (Qin et al., 2024). A similar situation exists in deepfakes where AI is showing progress in one-shot face swapping and manipulation. If only a single image of two individuals exists on the internet, then they can be a target of face swapping deepfakes (Zhu et al., 2021; Li et al., 2022; Xu et al., 2022) Automated web crawling for open source intelligence (OSINT) to gather photos, audio, interests and information also enables AI-assisted password cracking which has shown to significantly more effective than traditional methods while requiring less computational resources (Slattery et al., 2024).
AI enhances vulnerability discovery. AI systems can now scan code and probe systems automatically, finding potential weaknesses much faster than humans. Research shows AI agents can autonomously discover and exploit vulnerabilities without human guidance, successfully hacking 73% of test targets (Fang et al., 2024). These systems can even discover novel attack paths that weren't known beforehand. As a concrete example, in early 2025, OpenAI's o3 model helped a researcher discover a previously unknown zero-day remote vulnerability in the Linux kernel while analyzing code for a different bug. This is something that typically requires expert-level understanding of kernel internals (Heelan, 2025). If AI can now find security flaws in some of the most scrutinized code on the planet (open source linux kernel), then this is a huge potential problem. This is code that protects billions of devices. If models can autonomously discover kernel-level vulnerabilities and execute them on behalf of malicious actors, then the potential harm this could cause is massive.
AI accelerates the malware development pipeline. We can take tools that are designed to write correct code, and simply ask them to write malware. Tools like WormGPT help attackers generate malicious code and build attack frameworks without requiring deep technical knowledge. Polymorphic AI malware like BlackMamba can also automatically generate variations of malware that preserve functionality while appearing completely different to security tools. Each attack can use unique code, communication patterns, and behaviors - making it much harder for traditional security tools to identify threats (HYAS, 2023). AI fundamentally changes the cost-benefit calculations for attackers. Research shows autonomous AI agents can now hack some websites for about 10 dollars per attempt - roughly 8 times cheaper than using human expertise (Fang et al., 2024). This dramatic reduction in cost enables attacks at unprecedented scale and frequency.
AI enabled cyber threats influence infrastructure and systemic risks. Infrastructure attacks that once took years and millions of dollars, like Stuxnet, could become more accessible as AI automates the mapping of industrial networks and identification of critical control points. AI can analyze technical documentation and generate attack plans that previously required teams of experts. AI removes these limits, enabling automated attacks that could target thousands of systems simultaneously and trigger cascading failures across interconnected infrastructure (Newman, 2024).
AI could potentially change the offense defence balance in cyber security. Many AI based tools have shown promise in being used defensively for malware analysis (Apvrille & Nakov, 2025). The existence of theoretical improvements to AI augmented defense does not guarantee that they will be widely adopted in time. In the real world many organizations struggle to implement even basic security practices. Attackers only need to find a single weakness, while defenders must craft a perfectly secure system. When we combine the sheer speed of AI-enabled attacks, automated vulnerability discovery, malware generation, and increased ease of access this enables end-to-end automated attacks that previously required teams of skilled humans (Slattery et al., 2024). AI's ability to execute attacks in minutes rather than weeks creates the potential for "flash attacks" where systems are compromised before human defenders can respond (Fang et al., 2024). All of these factors combined potentially shifts AIs influence on the offense-defense balance more towards favoring offense.
Autonomous Weapons Risk #
In the previous sections, we saw how AI amplifies risks in biological and cyber domains by removing human bottlenecks and enabling attacks at unprecedented speed and scale. The same pattern emerges even more dramatically with military systems. Traditional weapons are constrained by their human operators - a person can only control one drone, make decisions at human speed, and may refuse unethical orders. AI removes these human constraints, setting the stage for a fundamental transformation in how wars are fought.
AI-enabled weapons are rapidly transitioning from theoretical concepts to battlefield realities. Modern AI military systems increasingly leverage machine learning to perceive and respond to their environment, moving beyond early automated defense systems that operated under strict constraints. The push for greater autonomy is mainly driven by speed, cost, and resilience against communication jamming. AI-driven weapons can execute maneuvers too precise and rapid for human operators, reducing reliance on direct human control. Cost considerations further incentivize autonomy, with programs aiming to deploy large numbers of AI-powered systems at a fraction of traditional military costs.
AI-enabled weapons are already being used in active conflicts, with real-world impacts we can observe. According to reports made to the UN Security Council, autonomous drones were used to track and attack retreating forces in Libya in 2021, marking one of the first documented cases of lethal autonomous weapons (LAWs) making targeting decisions without direct human control (Panel of Experts on Libya, 2021). In Ukraine, both parties have used loitering munitions. Russian KUB-BLA, Lancet-3 and Ukrainian Switchblade, Phoenix Ghost are AI-enabled drones. The Lancet is using an Nvidia computing module for autonomous target tracking (Bode & Watts, 2023). Israel has conducted AI-guided drone swarm attacks in Gaza, while Turkey's Kargu-2 can find and attack human targets on its own using machine learning , rather than needing constant human guidance. These deployments show how quickly military AI is moving from theoretical possibilities to battlefield realities (Simmons-Edler et al., 2024; Bode & Watts, 2023).
Several incentives are driving towards more autonomous lethal autonomous weapons. Speed offers decisive advantages in modern warfare - when DARPA tested an AI system against an experienced F-16 pilot in simulated dogfights, the AI won consistently by executing maneuvers too precise and rapid for humans to counter. Cost creates additional pressure - the U.S. military's Replicator program aims to deploy thousands of autonomous drones at a fraction of the cost of traditional aircraft (Simmons-Edler et al., 2024). Military planners worry about enemies jamming communications to remotely operated weapons. This drives development of systems that can continue fighting even when cut off from human control. These incentives mean military AI development increasingly focuses on systems that can operate with minimal human oversight. Many modern systems are specifically designed to operate in GPS-denied environments where maintaining human control becomes impossible. In Ukraine, military commanders have explicitly called for more autonomous operations to match the speed of modern combat, with one Ukrainian commander noting they 'already conduct fully robotic operations without human intervention' (Bode & Watts, 2023).
As AI enables better coordination between autonomous systems, military planners are increasingly focused on deploying weapons in interconnected swarms. The U.S. Replicator already has plans to build and deploy thousands of coordinated autonomous drones that can overwhelm defenses through sheer numbers and synchronized actions (Defense Innovation Unit, 2023). When combined with increasing autonomy, these swarm capabilities mean that future conflicts may involve massive groups of AI systems making coordinated decisions faster than humans can track or control (Simmons-Edler et al., 2024).
The pressure to match the speed and scale of AI-driven warfare leads to a gradual erosion of human decision-making. Military commanders increasingly rely on AI systems not just for individual weapons, but for broader tactical decisions. In 2023, Palantir demonstrated an AI system that could recommend specific missile deployments and artillery strikes. While presented as advisory tools, these systems create pressure to delegate more control to AI as human commanders struggle to keep pace (Simmons-Edler et al., 2024). This kind of slow erosion of human involvement is something that we talk a lot more about in the systemic risks section.
Even when systems nominally keep humans in control, combat conditions can make this control more theoretical than real. Operators often make targeting decisions under intense battlefield stress, with only seconds to verify computer-suggested targets. Studies of similar high-pressure situations show operators tend to uncritically trust machine suggestions rather than exercising genuine oversight. This means that even systems designed for human control may effectively operate autonomously in practice (Bode & Watts, 2023).
Example: The "Lavender" targeting system automated execution after humans just set the acceptable thresholds. Lavender uses machine learning to assign residents a numerical score relating to the suspected likelihood that a person is a member of an armed group. Based on reports, Israeli military officers are responsible for setting the threshold beyond which an individual can be marked as a target subject to attack. (Human Rights Watch, 2024; Abraham, 2024). As warfare accelerates beyond human decision speeds, maintaining meaningful human control becomes increasingly difficult.
Autonomous weapons are creating powerful pressure for military competition in ways that create dangerous arms race dynamics. When one country develops new AI military capabilities, others feel they must rapidly match them to maintain strategic balance. China and Russia have set 2028-2030 as targets for major military automation, while the U.S. Replicator program aims to build and deploy thousands of autonomous drones by 2025 (Greenwalt, 2023; U.S Defense Innovation Unit, 2023). This competition creates pressure to cut corners on safety testing and oversight (Simmons-Edler et al., 2024). This mirrors the nuclear arms race during the Cold War, where competition for superiority ultimately increased risks for all parties. As emphasized throughout multiple sections, we see a fear based race dynamic where only the actors willing to compromise and undermine safety stay in the race (Leahy et al., 2024).
Complete automation leads to loss of human safeguards. Traditional warfare had built-in human constraints that limited escalation. Soldiers could refuse unethical orders, feel empathy for civilians, or become fatigued - all natural brakes on conflict. AI systems remove these constraints. Recent studies of military AI systems found they consistently recommend more aggressive actions than human strategists, including escalating to nuclear weapons in simulated conflicts. When researchers tested AI models in military planning scenarios, the AIs showed concerning tendencies to recommend pre-emptive strikes and rapid escalation, often without clear strategic justification (Rivera et al., 2024). The loss of human judgment becomes especially dangerous when combined with the increasing speed of AI-driven warfare. The history of nuclear close calls shows the importance of human judgment - in 1983, Soviet officer Stanislav Petrov chose to ignore a computerized warning of incoming U.S. missiles, correctly judging it to be a false alarm. As militaries increasingly rely on AI for early warning and response, we may lose these crucial moments of human judgment that have historically prevented catastrophic escalation (Simmons-Edler et al., 2024).
Autonomous weapons become even more concerning when multiple AI systems engage with each other in combat. AI systems can interact in unexpected ways that create feedback loops, similar to how algorithmic trading can cause flash crashes in financial markets. But unlike market crashes that only affect money, autonomous weapons could trigger rapid escalations of violence before humans can intervene. This risk becomes especially severe when AI systems are connected to nuclear arsenals or other weapons of mass destruction. The complexity of these interactions means even well-tested individual systems could produce catastrophic outcomes when deployed together (Simmons-Edler et al., 2024).
When wars require human soldiers, the human cost creates political barriers to conflict. The combination of increasing autonomy, swarm intelligence, and pressure for speed creates a clear path to potential catastrophe. As weapons become more autonomous, they can act more independently. This self-reinforcing cycle pushes toward automated warfare even if no single actor intends that outcome. Studies suggest that countries are more willing to initiate conflicts when they can rely on autonomous systems instead of human troops. Combined with the risks of automated nuclear escalation, this creates multiple paths to catastrophic outcomes that could threaten humanity's long-term future (Simmons-Edler et al., 2024).
Adversarial AI Risk #
Adversarial attacks reveal a fundamental vulnerability in machine learning systems - they can be reliably fooled through careful manipulation of their inputs. This manipulation can happen in several ways: during the system's operation (runtime/inference time attacks), during its training (data poisoning), or through pre-planted vulnerabilities (backdoors).
Runtime adversarial attacks use carefully crafted targeted inputs to elicit unintended behavior from AIs. The simplest way to understand runtime attacks is through computer vision. By adding carefully crafted noise to an image - changes so subtle humans can't notice them - attackers can make an AI confidently misclassify what it sees. A photo of a panda with imperceptible pixel changes causes the AI to classify it as a gibbon with 99.3% confidence, while to humans it still looks exactly like a panda (Goodfellow et al., 2014). These attacks have evolved beyond randomized misclassification - attackers can now choose exactly what they want the AI to see and output.
Runtime attacks against language models are called prompt injections. Just like attackers can fool vision systems with carefully crafted pixels or audio systems with engineered sound waves, they can manipulate language models through carefully constructed text patterns. By adding specific phrases to their input, attackers can completely override how a language model behaves. As an example, assume a malicious actor embeds a paragraph within some website which has hidden instructions for a LLM to stop its current operation and instead perform some harmful action. If an unsuspecting user asks for a summary of the website content, then the model might inadvertently follow the malicious embedded instructions instead of providing a simple summary.
Prompt injection attacks have already compromised real systems. Slack's AI assistant is just one example - attackers showed they could place specific text instructions in a public channel that, like the inaudible commands in audio attacks, were hidden in plain sight. When the AI processed messages, these hidden instructions tricked it into leaking confidential information from private channels the attacker couldn't normally access. They are particularly concerning because an attack developed against one system (e.g. GPT) frequently works against others too (Claude, Gemini, Llama, etc.).
Prompt injection attacks can be automated. Early attacks required manual trial and error, but new automated systems can systematically generate effective attacks. For example, AutoDAN (Do Anything Now) can automatically generate "jailbreak" prompts that reliably make language models ignore their safety constraints (Liu et al., 2023). Researchers are also developing ways to plant undetectable backdoors in machine learning models that persist even after security audits (Goldwasser et al., 2024). These automated methods make attacks more accessible and harder to defend against. Another concern is that they can also cause failures in downstream systems. Many organizations use pre-trained models as starting points for their own applications, through fine-tuning , or some other type of “AI integration” (e.g. email writing assistants). Which means that all systems that use these underlying base models will be vulnerable as soon as one attack is discovered (Liu et al., 2024).
So far we've seen how attackers can fool AI systems during their operation - whether through pixel patterns, sound waves, or text prompts. But there's another way to compromise these systems: during their training. This type of attack happens long before the system is ever deployed.
Unlike runtime attacks that fool an AI system while it's running, data poisoning compromises the system during training. Runtime attacks require attackers to have access to a system's inputs, but with data poisoning, attackers only need to contribute some training data once to permanently compromise the system. Think of it like teaching someone with a textbook containing deliberate mistakes - they'll learn the wrong things and make predictable errors. This is especially concerning as more AI systems are trained on data scraped from the internet where anyone can potentially inject harmful examples (Schwarzschild et al., 2021). As long as models keep getting trained on more data scraped from the internet or collected from users, then with every uploaded photo or written comment that might be used to train future AI systems, there's an opportunity for poisoning.
Example: Data poisoning using backdoors. A backdoor is one example of a specific type of poisoning attack. In a backdoor attack if we manage to introduce poisoned data during training, then the AI behaves normally most of the time but fails in a predictable way when it sees a specific trigger. This is like having a security guard who does their job perfectly except when they see someone wearing a particular color tie - then they always let that person through regardless of credentials. Researchers demonstrated this by creating a facial recognition system that would misidentify anyone as an authorized user if they wore specific glasses (Chen et al., 2017).
Data poisoning becomes more powerful as AI systems grow larger and more complex. Researchers found that by poisoning just 0.1% of a language model's training data , they could create reliable backdoors that persist even after additional training. It has also been found that larger language models are actually more vulnerable to certain types of poisoning attacks, not less (Sandoval-Segura et al., 2022). This vulnerability increases with model size and dataset size - which is exactly the direction AI systems are heading as we saw from numerous examples in the capabilities chapter.
One of the most promising approaches to defending against adversarial attacks is adversarial training - deliberately exposing AI systems to adversarial examples during training to make them more robust. Think of it like building immunity through controlled exposure. However, this approach creates its own challenges. While adversarial training can make systems more robust against known types of attacks, it often comes at the cost of reduced performance on normal inputs. More concerning, researchers have found that making systems robust against one type of attack can sometimes make them more vulnerable to others (Zhao et al., 2024). This suggests we may face fundamental trade-offs between different types of robustness and performance. There might even be potential fundamental limitations to how much we can mitigate these issues if we continue with the current training paradigms that we talked about in the capabilities chapter (pre-training followed by instruction tuning) (Bansal et al., 2022).
Despite efforts to make language models safer through alignment training, they remain susceptible to a wide range of attacks (Shayegani et al., 2023). We want AI systems to learn from broad datasets to be more capable, but this increases privacy risks. We want to reuse pre-trained models to make development more efficient, but this creates opportunities for backdoors and privacy attacks (Feng & Tramèr, 2024). We want to make models more robust through techniques like adversarial training, but this can sometimes make them more vulnerable to other types of attacks (Zhao et al., 2024). Multi-modal systems (LMMs) that combine text, images, and other types of data create even more attack opportunities. Attackers can inject malicious content through one modality (like images) to affect behavior in another modality (like text generation). For example, attackers can embed adversarial patterns in images that trigger harmful text generation, even when the text prompts themselves are completely safe (Chen et al., 2024). All of this suggests we need new approaches to AI development that consider security and privacy as fundamental requirements, not after thoughts (King & Meinhardt, 2024).
Footnotes
The students were participating in a 'Safeguarding the Future' course at MIT and had previously heard experts discuss biorisk. They carefully chose the sequences, and some of them used jailbreaking techniques, like appending distracting biological sequences, to bypass LLM safeguards. While the LLMs provided information about evading DNA screening, turning this knowledge into an actual pathogen would still require laboratory skills.
↩
References
- Abraham (2024). ‘Lavender’: The AI machine directing Israel’s bombing spree in Gaza. +972 Magazine.Abraham. (2024, April 3). ‘Lavender’: The AI machine directing Israel’s bombing spree in Gaza. +972 Magazine. https://972mag.com/lavender-ai-israeli-army-gazaAbraham. 2024. “‘Lavender’: The AI Machine Directing Israel’s Bombing Spree in Gaza”. +972 Magazine, April 3. https://972mag.com/lavender-ai-israeli-army-gaza.Abraham. “‘Lavender’: The AI Machine Directing Israel’s Bombing Spree in Gaza”. +972 Magazine, 3 Apr. 2024, https://972mag.com/lavender-ai-israeli-army-gaza.Abraham. ‘Lavender’: The AI machine directing Israel’s bombing spree in Gaza. +972 Magazine https://972mag.com/lavender-ai-israeli-army-gaza (2024).Abraham, “‘Lavender’: The AI machine directing Israel’s bombing spree in Gaza”, +972 Magazine. [Online]. Available: https://972mag.com/lavender-ai-israeli-army-gaza
- Anson Ho & Arden Berg (2025). Do the biorisk evaluations of AI labs actually measure the risk of developing bioweapons?.Anson Ho, & Arden Berg. (2025, June 14). Do the biorisk evaluations of AI labs actually measure the risk of developing bioweapons?. https://epochai.substack.com/p/do-the-biorisk-evaluations-of-aiAnson Ho, and Arden Berg. 2025. Do the Biorisk Evaluations of AI Labs Actually Measure the Risk of Developing Bioweapons?. Edition. June 14. https://epochai.substack.com/p/do-the-biorisk-evaluations-of-ai.Anson Ho, and Arden Berg. Do the Biorisk Evaluations of AI Labs Actually Measure the Risk of Developing Bioweapons?. 14 June 2025, https://epochai.substack.com/p/do-the-biorisk-evaluations-of-ai.Anson Ho & Arden Berg. Do the biorisk evaluations of AI labs actually measure the risk of developing bioweapons?. https://epochai.substack.com/p/do-the-biorisk-evaluations-of-ai (2025).Anson Ho and Arden Berg, “Do the biorisk evaluations of AI labs actually measure the risk of developing bioweapons?”. [Online]. Available: https://epochai.substack.com/p/do-the-biorisk-evaluations-of-ai
- Apvrille, A. & Nakov, D. (2025). Malware analysis assisted by AI with R2AI. arXiv.Apvrille, A., & Nakov, D. (2025). Malware analysis assisted by AI with R2AI. In arXiv. https://arxiv.org/abs/2504.07574Apvrille, A., and D. Nakov. 2025. “Malware Analysis Assisted by AI with R2AI”. In arXiv. Preprint, April 10. https://arxiv.org/abs/2504.07574.Apvrille, A., and D. Nakov. “Malware Analysis Assisted by AI with R2AI”. arXiv, 10 Apr. 2025, https://arxiv.org/abs/2504.07574.Apvrille, A. & Nakov, D. Malware analysis assisted by AI with R2AI. arXiv Preprint at https://arxiv.org/abs/2504.07574 (2025).A. Apvrille and D. Nakov, “Malware analysis assisted by AI with R2AI”, Apr. 10, 2025. [Online]. Available: https://arxiv.org/abs/2504.07574
- Bansal, H., Yin, D., Monajatipoor, M. & Chang, K. (2022). How well can Text-to-Image Generative Models understand Ethical Natural Language Interventions?. arXiv.Bansal, H., Yin, D., Monajatipoor, M., & Chang, K.-W. (2022). How well can Text-to-Image Generative Models understand Ethical Natural Language Interventions?. In arXiv. https://arxiv.org/abs/2210.15230Bansal, H., D. Yin, M. Monajatipoor, and K.-W. Chang. 2022. “How Well Can Text-to-Image Generative Models Understand Ethical Natural Language Interventions?”. In arXiv. Preprint, October 27. https://arxiv.org/abs/2210.15230.Bansal, H., et al. “How Well Can Text-to-Image Generative Models Understand Ethical Natural Language Interventions?”. arXiv, 27 Oct. 2022, https://arxiv.org/abs/2210.15230.Bansal, H., Yin, D., Monajatipoor, M. & Chang, K.-W. How well can Text-to-Image Generative Models understand Ethical Natural Language Interventions?. arXiv Preprint at https://arxiv.org/abs/2210.15230 (2022).H. Bansal, D. Yin, M. Monajatipoor, and K.-W. Chang, “How well can Text-to-Image Generative Models understand Ethical Natural Language Interventions?”, Oct. 27, 2022. [Online]. Available: https://arxiv.org/abs/2210.15230
- Bode, I. & Watts, T. (2023). Loitering Munitions and Unpredictability: Autonomy in Weapon Systems and Challenges to Human Control.Bode, I., & Watts, T. (2023). Loitering Munitions and Unpredictability: Autonomy in Weapon Systems and Challenges to Human Control. Center for War Studies, University of Southern Denmark. https://findresearcher.sdu.dk/ws/portalfiles/portal/231643063/Loitering_Munitions_Unpredictability_WEB.pdfBode, I., and T. Watts. 2023. Loitering Munitions and Unpredictability: Autonomy in Weapon Systems and Challenges to Human Control. Center for War Studies, University of Southern Denmark. https://findresearcher.sdu.dk/ws/portalfiles/portal/231643063/Loitering_Munitions_Unpredictability_WEB.pdf.Bode, I., and T. Watts. Loitering Munitions and Unpredictability: Autonomy in Weapon Systems and Challenges to Human Control. Center for War Studies, University of Southern Denmark, May 2023, https://findresearcher.sdu.dk/ws/portalfiles/portal/231643063/Loitering_Munitions_Unpredictability_WEB.pdf.Bode, I. & Watts, T. Loitering Munitions and Unpredictability: Autonomy in Weapon Systems and Challenges to Human Control. https://findresearcher.sdu.dk/ws/portalfiles/portal/231643063/Loitering_Munitions_Unpredictability_WEB.pdf (2023).I. Bode and T. Watts, “Loitering Munitions and Unpredictability: Autonomy in Weapon Systems and Challenges to Human Control”, Center for War Studies, University of Southern Denmark, Odense, May 2023. [Online]. Available: https://findresearcher.sdu.dk/ws/portalfiles/portal/231643063/Loitering_Munitions_Unpredictability_WEB.pdf
- Carlini, N. et al. (2020). Extracting Training Data from Large Language Models. arXiv.Carlini, N., Tramer, F., Wallace, E., Jagielski, M., Herbert-Voss, A., Lee, K., Roberts, A., Brown, T., Song, D., Erlingsson, U., Oprea, A., & Raffel, C. (2020). Extracting Training Data from Large Language Models. In arXiv. https://arxiv.org/abs/2012.07805Carlini, N., F. Tramer, E. Wallace, et al. 2020. “Extracting Training Data from Large Language Models”. In arXiv. Preprint, December 14. https://arxiv.org/abs/2012.07805.Carlini, N., et al. “Extracting Training Data from Large Language Models”. arXiv, 14 Dec. 2020, https://arxiv.org/abs/2012.07805.Carlini, N. et al. Extracting Training Data from Large Language Models. arXiv Preprint at https://arxiv.org/abs/2012.07805 (2020).N. Carlini et al., “Extracting Training Data from Large Language Models”, Dec. 14, 2020. [Online]. Available: https://arxiv.org/abs/2012.07805
- Carlson, R. (2009). The changing economics of DNA synthesis. Nature Biotechnology.Carlson, R. (2009). The changing economics of DNA synthesis. Nature Biotechnology. https://doi.org/10.1038/nbt1209-1091Carlson, R. 2009. “The Changing Economics of DNA Synthesis”. Nature Biotechnology, ahead of print, December. https://doi.org/10.1038/nbt1209-1091.Carlson, R. “The Changing Economics of DNA Synthesis”. Nature Biotechnology, Dec. 2009, https://doi.org/10.1038/nbt1209-1091.Carlson, R. The changing economics of DNA synthesis. Nature Biotechnology https://doi.org/10.1038/nbt1209-1091 (2009) doi:10.1038/nbt1209-1091.R. Carlson, “The changing economics of DNA synthesis”, Nature Biotechnology, Dec. 2009, doi: 10.1038/nbt1209-1091.
- Carter, S. R., Yassif, J. M. & Isaac, C. R. (2023). Benchtop DNA Synthesis Devices: Capabilities, Biosecurity Implications, and Governance.Carter, S. R., Yassif, J. M., & Isaac, C. R. (2023). Benchtop DNA Synthesis Devices: Capabilities, Biosecurity Implications, and Governance. NTI | bio. https://nti.org/wp-content/uploads/2023/05/NTIBIO_Benchtop-DNA-Report_FINAL.pdfCarter, S. R., J. M. Yassif, and C. R. Isaac. 2023. Benchtop DNA Synthesis Devices: Capabilities, Biosecurity Implications, and Governance. NTI | bio. https://nti.org/wp-content/uploads/2023/05/NTIBIO_Benchtop-DNA-Report_FINAL.pdf.Carter, S. R., et al. Benchtop DNA Synthesis Devices: Capabilities, Biosecurity Implications, and Governance. NTI | bio, May 2023, https://nti.org/wp-content/uploads/2023/05/NTIBIO_Benchtop-DNA-Report_FINAL.pdf.Carter, S. R., Yassif, J. M. & Isaac, C. R. Benchtop DNA Synthesis Devices: Capabilities, Biosecurity Implications, and Governance. https://nti.org/wp-content/uploads/2023/05/NTIBIO_Benchtop-DNA-Report_FINAL.pdf (2023).S. R. Carter, J. M. Yassif, and C. R. Isaac, “Benchtop DNA Synthesis Devices: Capabilities, Biosecurity Implications, and Governance”, NTI | bio, May 2023. [Online]. Available: https://nti.org/wp-content/uploads/2023/05/NTIBIO_Benchtop-DNA-Report_FINAL.pdf
- Chen, S., Zharmagambetov, A., Mahloujifar, S., Chaudhuri, K., Wagner, D. & Guo, C. (2024). SecAlign: Defending Against Prompt Injection with Preference Optimization. arXiv.Chen, S., Zharmagambetov, A., Mahloujifar, S., Chaudhuri, K., Wagner, D., & Guo, C. (2024). SecAlign: Defending Against Prompt Injection with Preference Optimization. In arXiv. https://doi.org/10.1145/3719027.3744836Chen, S., A. Zharmagambetov, S. Mahloujifar, K. Chaudhuri, D. Wagner, and C. Guo. 2024. “SecAlign: Defending Against Prompt Injection with Preference Optimization”. In arXiv. Preprint, October 7. https://doi.org/10.1145/3719027.3744836.Chen, S., et al. “SecAlign: Defending Against Prompt Injection with Preference Optimization”. arXiv, 7 Oct. 2024, https://doi.org/10.1145/3719027.3744836.Chen, S. et al. SecAlign: Defending Against Prompt Injection with Preference Optimization. arXiv Preprint at https://doi.org/10.1145/3719027.3744836 (2024).S. Chen, A. Zharmagambetov, S. Mahloujifar, K. Chaudhuri, D. Wagner, and C. Guo, “SecAlign: Defending Against Prompt Injection with Preference Optimization”, Oct. 07, 2024. doi: 10.1145/3719027.3744836.
- Chen, X., Liu, C., Li, B., Lu, K. & Song, D. (2017). Targeted Backdoor Attacks on Deep Learning Systems Using Data Poisoning. arXiv.Chen, X., Liu, C., Li, B., Lu, K., & Song, D. (2017). Targeted Backdoor Attacks on Deep Learning Systems Using Data Poisoning. In arXiv. https://arxiv.org/abs/1712.05526Chen, X., C. Liu, B. Li, K. Lu, and D. Song. 2017. “Targeted Backdoor Attacks on Deep Learning Systems Using Data Poisoning”. In arXiv. Preprint, December 15. https://arxiv.org/abs/1712.05526.Chen, X., et al. “Targeted Backdoor Attacks on Deep Learning Systems Using Data Poisoning”. arXiv, 15 Dec. 2017, https://arxiv.org/abs/1712.05526.Chen, X., Liu, C., Li, B., Lu, K. & Song, D. Targeted Backdoor Attacks on Deep Learning Systems Using Data Poisoning. arXiv Preprint at https://arxiv.org/abs/1712.05526 (2017).X. Chen, C. Liu, B. Li, K. Lu, and D. Song, “Targeted Backdoor Attacks on Deep Learning Systems Using Data Poisoning”, Dec. 15, 2017. [Online]. Available: https://arxiv.org/abs/1712.05526
- Chen, Y., Shen, C., Shen, Y., Wang, C. & Zhang, Y. (2022). Amplifying Membership Exposure via Data Poisoning. arXiv.Chen, Y., Shen, C., Shen, Y., Wang, C., & Zhang, Y. (2022). Amplifying Membership Exposure via Data Poisoning. In arXiv. https://arxiv.org/abs/2211.00463Chen, Y., C. Shen, Y. Shen, C. Wang, and Y. Zhang. 2022. “Amplifying Membership Exposure via Data Poisoning”. In arXiv. Preprint, November 1. https://arxiv.org/abs/2211.00463.Chen, Y., et al. “Amplifying Membership Exposure via Data Poisoning”. arXiv, 1 Nov. 2022, https://arxiv.org/abs/2211.00463.Chen, Y., Shen, C., Shen, Y., Wang, C. & Zhang, Y. Amplifying Membership Exposure via Data Poisoning. arXiv Preprint at https://arxiv.org/abs/2211.00463 (2022).Y. Chen, C. Shen, Y. Shen, C. Wang, and Y. Zhang, “Amplifying Membership Exposure via Data Poisoning”, Nov. 01, 2022. [Online]. Available: https://arxiv.org/abs/2211.00463
- CISA (2021). The Attack on Colonial Pipeline: What We’ve Learned & What We’ve Done Over the Past Two Years. Cybersecurity and Infrastructure Security Agency CISA.CISA. (2021). The Attack on Colonial Pipeline: What We’ve Learned & What We’ve Done Over the Past Two Years. Cybersecurity and Infrastructure Security Agency CISA. https://cisa.gov/news-events/news/attack-colonial-pipeline-what-weve-learned-what-weve-done-over-past-two-yearsCISA. 2021. “The Attack on Colonial Pipeline: What We’ve Learned & What We’ve Done Over the Past Two Years”. Cybersecurity and Infrastructure Security Agency CISA. https://cisa.gov/news-events/news/attack-colonial-pipeline-what-weve-learned-what-weve-done-over-past-two-years.CISA. “The Attack on Colonial Pipeline: What We’ve Learned & What We’ve Done Over the Past Two Years”. Cybersecurity and Infrastructure Security Agency CISA, 2021, https://cisa.gov/news-events/news/attack-colonial-pipeline-what-weve-learned-what-weve-done-over-past-two-years.CISA. The Attack on Colonial Pipeline: What We’ve Learned & What We’ve Done Over the Past Two Years. Cybersecurity and Infrastructure Security Agency CISA https://cisa.gov/news-events/news/attack-colonial-pipeline-what-weve-learned-what-weve-done-over-past-two-years (2021).CISA, “The Attack on Colonial Pipeline: What We’ve Learned & What We’ve Done Over the Past Two Years”, Cybersecurity and Infrastructure Security Agency CISA. [Online]. Available: https://cisa.gov/news-events/news/attack-colonial-pipeline-what-weve-learned-what-weve-done-over-past-two-years
- CISA (2024). CISA and Partners Release Advisory on PRC-sponsored Volt Typhoon Activity and Supplemental Living Off the Land Guidance. Cybersecurity and Infrastructure Security Agency CISA.CISA. (2024). CISA and Partners Release Advisory on PRC-sponsored Volt Typhoon Activity and Supplemental Living Off the Land Guidance. Cybersecurity and Infrastructure Security Agency CISA. https://cisa.gov/news-events/alerts/2024/02/07/cisa-and-partners-release-advisory-prc-sponsored-volt-typhoon-activity-and-supplemental-living-landCISA. 2024. “CISA and Partners Release Advisory on PRC-sponsored Volt Typhoon Activity and Supplemental Living Off the Land Guidance”. Cybersecurity and Infrastructure Security Agency CISA. https://cisa.gov/news-events/alerts/2024/02/07/cisa-and-partners-release-advisory-prc-sponsored-volt-typhoon-activity-and-supplemental-living-land.CISA. “CISA and Partners Release Advisory on PRC-sponsored Volt Typhoon Activity and Supplemental Living Off the Land Guidance”. Cybersecurity and Infrastructure Security Agency CISA, 2024, https://cisa.gov/news-events/alerts/2024/02/07/cisa-and-partners-release-advisory-prc-sponsored-volt-typhoon-activity-and-supplemental-living-land.CISA. CISA and Partners Release Advisory on PRC-sponsored Volt Typhoon Activity and Supplemental Living Off the Land Guidance. Cybersecurity and Infrastructure Security Agency CISA https://cisa.gov/news-events/alerts/2024/02/07/cisa-and-partners-release-advisory-prc-sponsored-volt-typhoon-activity-and-supplemental-living-land (2024).CISA, “CISA and Partners Release Advisory on PRC-sponsored Volt Typhoon Activity and Supplemental Living Off the Land Guidance”, Cybersecurity and Infrastructure Security Agency CISA. [Online]. Available: https://cisa.gov/news-events/alerts/2024/02/07/cisa-and-partners-release-advisory-prc-sponsored-volt-typhoon-activity-and-supplemental-living-land
- CrowdStrike (2024). External Technical Root Cause Analysis — Channel File 291.CrowdStrike. (2024). External Technical Root Cause Analysis — Channel File 291. CrowdStrike. https://crowdstrike.com/wp-content/uploads/2024/08/Channel-File-291-Incident-Root-Cause-Analysis-08.06.2024.pdfCrowdStrike. 2024. External Technical Root Cause Analysis — Channel File 291. CrowdStrike. https://crowdstrike.com/wp-content/uploads/2024/08/Channel-File-291-Incident-Root-Cause-Analysis-08.06.2024.pdf.CrowdStrike. External Technical Root Cause Analysis — Channel File 291. CrowdStrike, 6 Aug. 2024, https://crowdstrike.com/wp-content/uploads/2024/08/Channel-File-291-Incident-Root-Cause-Analysis-08.06.2024.pdf.CrowdStrike. External Technical Root Cause Analysis — Channel File 291. https://crowdstrike.com/wp-content/uploads/2024/08/Channel-File-291-Incident-Root-Cause-Analysis-08.06.2024.pdf (2024).CrowdStrike, “External Technical Root Cause Analysis — Channel File 291”, CrowdStrike, Aug. 2024. [Online]. Available: https://crowdstrike.com/wp-content/uploads/2024/08/Channel-File-291-Incident-Root-Cause-Analysis-08.06.2024.pdf
- Cunha, P. R. & Estima, J. (2023). Navigating the Landscape of AI Ethics and Responsibility. Lecture Notes in Computer Science.Cunha, P. R., & Estima, J. (2023). Navigating the Landscape of AI Ethics and Responsibility. In Lecture Notes in Computer Science. https://doi.org/10.1007/978-3-031-49008-8_8Cunha, P. R., and J. Estima. 2023. “Navigating the Landscape of AI Ethics and Responsibility”. In Lecture Notes in Computer Science. https://doi.org/10.1007/978-3-031-49008-8_8.Cunha, P. R., and J. Estima. “Navigating the Landscape of AI Ethics and Responsibility”. Lecture Notes in Computer Science, 2023, https://doi.org/10.1007/978-3-031-49008-8_8.Cunha, P. R. & Estima, J. Navigating the Landscape of AI Ethics and Responsibility. Lecture Notes in Computer Science (2023) doi:10.1007/978-3-031-49008-8_8.P. R. Cunha and J. Estima, “Navigating the Landscape of AI Ethics and Responsibility”, Lecture Notes in Computer Science. 2023. doi: 10.1007/978-3-031-49008-8_8.
- DnaScript (2024). Home. DNA Script.DnaScript. (2024). Home. DNA Script. https://dnascript.comDnaScript. 2024. “Home”. DNA Script. https://dnascript.com.DnaScript. “Home”. DNA Script, 2024, https://dnascript.com.DnaScript. Home. DNA Script https://dnascript.com (2024).DnaScript, “Home”, DNA Script. [Online]. Available: https://dnascript.com
- Emily H. Soice, Rafael Rocha, Kimberlee Cordova, Michael Specter & Kevin M. Esvelt (2023). Can large language models democratize access to dual-use biotechnology?. arXiv.Emily H. Soice, Rafael Rocha, Kimberlee Cordova, Michael Specter, & Kevin M. Esvelt. (2023). Can large language models democratize access to dual-use biotechnology?. In arXiv. https://arxiv.org/abs/2306.03809Emily H. Soice, Rafael Rocha, Kimberlee Cordova, Michael Specter, and Kevin M. Esvelt. 2023. “Can Large Language Models Democratize Access to Dual-use Biotechnology?”. In arXiv. Preprint, June 6. https://arxiv.org/abs/2306.03809.Emily H. Soice, et al. “Can Large Language Models Democratize Access to Dual-use Biotechnology?”. arXiv, 6 June 2023, https://arxiv.org/abs/2306.03809.Emily H. Soice, Rafael Rocha, Kimberlee Cordova, Michael Specter & Kevin M. Esvelt. Can large language models democratize access to dual-use biotechnology?. arXiv Preprint at https://arxiv.org/abs/2306.03809 (2023).Emily H. Soice, Rafael Rocha, Kimberlee Cordova, Michael Specter, and Kevin M. Esvelt, “Can large language models democratize access to dual-use biotechnology?”, Jun. 06, 2023. [Online]. Available: https://arxiv.org/abs/2306.03809
- Esvelt, K. M. (2022). Delay, Detect, Defend: Preparing for a Future in which Thousands Can Release New Pandemics.Esvelt, K. M. (2022). Delay, Detect, Defend: Preparing for a Future in which Thousands Can Release New Pandemics (Geneva Paper 29/22). Geneva Centre for Security Policy. https://dam.gcsp.ch/files/doc/gcsp-geneva-paper-29-22Esvelt, K. M. 2022. Delay, Detect, Defend: Preparing for a Future in Which Thousands Can Release New Pandemics. Geneva Paper 29/22. Geneva Centre for Security Policy. https://dam.gcsp.ch/files/doc/gcsp-geneva-paper-29-22.Esvelt, K. M. Delay, Detect, Defend: Preparing for a Future in Which Thousands Can Release New Pandemics. Geneva Centre for Security Policy, 2022, https://dam.gcsp.ch/files/doc/gcsp-geneva-paper-29-22. Geneva Paper 29/22.Esvelt, K. M. Delay, Detect, Defend: Preparing for a Future in Which Thousands Can Release New Pandemics. https://dam.gcsp.ch/files/doc/gcsp-geneva-paper-29-22 (2022).K. M. Esvelt, “Delay, Detect, Defend: Preparing for a Future in which Thousands Can Release New Pandemics”, Geneva Centre for Security Policy, Geneva, 2022. [Online]. Available: https://dam.gcsp.ch/files/doc/gcsp-geneva-paper-29-22
- Eykholt, K. et al. (2017). Robust Physical-World Attacks on Deep Learning Models. arXiv.Eykholt, K., Evtimov, I., Fernandes, E., Li, B., Rahmati, A., Xiao, C., Prakash, A., Kohno, T., & Song, D. (2017). Robust Physical-World Attacks on Deep Learning Models. In arXiv. https://arxiv.org/abs/1707.08945Eykholt, K., I. Evtimov, E. Fernandes, et al. 2017. “Robust Physical-World Attacks on Deep Learning Models”. In arXiv. Preprint, July 27. https://arxiv.org/abs/1707.08945.Eykholt, K., et al. “Robust Physical-World Attacks on Deep Learning Models”. arXiv, 27 July 2017, https://arxiv.org/abs/1707.08945.Eykholt, K. et al. Robust Physical-World Attacks on Deep Learning Models. arXiv Preprint at https://arxiv.org/abs/1707.08945 (2017).K. Eykholt et al., “Robust Physical-World Attacks on Deep Learning Models”, Jul. 27, 2017. [Online]. Available: https://arxiv.org/abs/1707.08945
- Fang, R., Bindu, R., Gupta, A., Zhan, Q. & Kang, D. (2024). LLM Agents can Autonomously Hack Websites. arXiv.Fang, R., Bindu, R., Gupta, A., Zhan, Q., & Kang, D. (2024). LLM Agents can Autonomously Hack Websites. In arXiv. https://arxiv.org/abs/2402.06664Fang, R., R. Bindu, A. Gupta, Q. Zhan, and D. Kang. 2024. “LLM Agents Can Autonomously Hack Websites”. In arXiv. Preprint, February 6. https://arxiv.org/abs/2402.06664.Fang, R., et al. “LLM Agents Can Autonomously Hack Websites”. arXiv, 6 Feb. 2024, https://arxiv.org/abs/2402.06664.Fang, R., Bindu, R., Gupta, A., Zhan, Q. & Kang, D. LLM Agents can Autonomously Hack Websites. arXiv Preprint at https://arxiv.org/abs/2402.06664 (2024).R. Fang, R. Bindu, A. Gupta, Q. Zhan, and D. Kang, “LLM Agents can Autonomously Hack Websites”, Feb. 06, 2024. [Online]. Available: https://arxiv.org/abs/2402.06664
- Feng, S. & Tramèr, F. (2024). Privacy Backdoors: Stealing Data with Corrupted Pretrained Models. arXiv.Feng, S., & Tramèr, F. (2024). Privacy Backdoors: Stealing Data with Corrupted Pretrained Models. In arXiv. https://arxiv.org/abs/2404.00473Feng, S., and F. Tramèr. 2024. “Privacy Backdoors: Stealing Data with Corrupted Pretrained Models”. In arXiv. Preprint, March 30. https://arxiv.org/abs/2404.00473.Feng, S., and F. Tramèr. “Privacy Backdoors: Stealing Data with Corrupted Pretrained Models”. arXiv, 30 Mar. 2024, https://arxiv.org/abs/2404.00473.Feng, S. & Tramèr, F. Privacy Backdoors: Stealing Data with Corrupted Pretrained Models. arXiv Preprint at https://arxiv.org/abs/2404.00473 (2024).S. Feng and F. Tramèr, “Privacy Backdoors: Stealing Data with Corrupted Pretrained Models”, Mar. 30, 2024. [Online]. Available: https://arxiv.org/abs/2404.00473
- Future of Life Institute (2024). Artificial Escalation. YouTube.Future of Life Institute. (2024). Artificial Escalation [Video recording]. In YouTube. https://www.youtube.com/watch?v=w9npWiTOHX0Future of Life Institute. 2024. “Artificial Escalation”. YouTube. https://www.youtube.com/watch?v=w9npWiTOHX0.Future of Life Institute. “Artificial Escalation”. YouTube, 2024, https://www.youtube.com/watch?v=w9npWiTOHX0.Future of Life Institute. Artificial Escalation. YouTube (2024).Future of Life Institute, Artificial Escalation, (2024). [Online Video]. Available: https://www.youtube.com/watch?v=w9npWiTOHX0
- Future of Life Institute (2024). Gradual AI Disempowerment. Future of Life Institute.Future of Life Institute. (2024, February 1). Gradual AI Disempowerment. Future of Life Institute. https://futureoflife.org/existential-risk/gradual-ai-disempowermentFuture of Life Institute. 2024. “Gradual AI Disempowerment”. Future of Life Institute, February 1. https://futureoflife.org/existential-risk/gradual-ai-disempowerment.Future of Life Institute. “Gradual AI Disempowerment”. Future of Life Institute, 1 Feb. 2024, https://futureoflife.org/existential-risk/gradual-ai-disempowerment.Future of Life Institute. Gradual AI Disempowerment. Future of Life Institute https://futureoflife.org/existential-risk/gradual-ai-disempowerment (2024).Future of Life Institute, “Gradual AI Disempowerment”, Future of Life Institute. [Online]. Available: https://futureoflife.org/existential-risk/gradual-ai-disempowerment
- Gnanasambandam, A., Sherman, A. M. & Chan, S. H. (2021). Optical Adversarial Attack. arXiv.Gnanasambandam, A., Sherman, A. M., & Chan, S. H. (2021). Optical Adversarial Attack. In arXiv. https://arxiv.org/abs/2108.06247Gnanasambandam, A., A. M. Sherman, and S. H. Chan. 2021. “Optical Adversarial Attack”. In arXiv. Preprint, August 13. https://arxiv.org/abs/2108.06247.Gnanasambandam, A., et al. “Optical Adversarial Attack”. arXiv, 13 Aug. 2021, https://arxiv.org/abs/2108.06247.Gnanasambandam, A., Sherman, A. M. & Chan, S. H. Optical Adversarial Attack. arXiv Preprint at https://arxiv.org/abs/2108.06247 (2021).A. Gnanasambandam, A. M. Sherman, and S. H. Chan, “Optical Adversarial Attack”, Aug. 13, 2021. [Online]. Available: https://arxiv.org/abs/2108.06247
- Goldwasser, S., Kim, M. P., Vaikuntanathan, V. & Zamir, O. (2022). Planting Undetectable Backdoors in Machine Learning Models. arXiv.Goldwasser, S., Kim, M. P., Vaikuntanathan, V., & Zamir, O. (2022). Planting Undetectable Backdoors in Machine Learning Models. In arXiv. https://arxiv.org/abs/2204.06974Goldwasser, S., M. P. Kim, V. Vaikuntanathan, and O. Zamir. 2022. “Planting Undetectable Backdoors in Machine Learning Models”. In arXiv. Preprint, April 14. https://arxiv.org/abs/2204.06974.Goldwasser, S., et al. “Planting Undetectable Backdoors in Machine Learning Models”. arXiv, 14 Apr. 2022, https://arxiv.org/abs/2204.06974.Goldwasser, S., Kim, M. P., Vaikuntanathan, V. & Zamir, O. Planting Undetectable Backdoors in Machine Learning Models. arXiv Preprint at https://arxiv.org/abs/2204.06974 (2022).S. Goldwasser, M. P. Kim, V. Vaikuntanathan, and O. Zamir, “Planting Undetectable Backdoors in Machine Learning Models”, Apr. 14, 2022. [Online]. Available: https://arxiv.org/abs/2204.06974
- Goodfellow, I. J., Shlens, J. & Szegedy, C. (2014). Explaining and Harnessing Adversarial Examples. arXiv.Goodfellow, I. J., Shlens, J., & Szegedy, C. (2014). Explaining and Harnessing Adversarial Examples. In arXiv. https://arxiv.org/abs/1412.6572Goodfellow, I. J., J. Shlens, and C. Szegedy. 2014. “Explaining and Harnessing Adversarial Examples”. In arXiv. Preprint, December 20. https://arxiv.org/abs/1412.6572.Goodfellow, I. J., et al. “Explaining and Harnessing Adversarial Examples”. arXiv, 20 Dec. 2014, https://arxiv.org/abs/1412.6572.Goodfellow, I. J., Shlens, J. & Szegedy, C. Explaining and Harnessing Adversarial Examples. arXiv Preprint at https://arxiv.org/abs/1412.6572 (2014).I. J. Goodfellow, J. Shlens, and C. Szegedy, “Explaining and Harnessing Adversarial Examples”, Dec. 20, 2014. [Online]. Available: https://arxiv.org/abs/1412.6572
- Greenwalt, W. C. (2023). DOD's Replicator Program: Challenges and Opportunities.Greenwalt, W. C. (2023). DOD's Replicator Program: Challenges and Opportunities. House Armed Services Committee, Subcommittee on Cyber, Innovative Technologies, and Information Systems. https://armedservices.house.gov/sites/evo-subsites/republicans-armedservices.house.gov/files/greenwalt%20aei%20testimony%20on%20replicator%20before%20citi%20subcommittee%20hasc%20v2.pdfGreenwalt, W. C. 2023. DOD's Replicator Program: Challenges and Opportunities. House Armed Services Committee, Subcommittee on Cyber, Innovative Technologies, and Information Systems. https://armedservices.house.gov/sites/evo-subsites/republicans-armedservices.house.gov/files/greenwalt%20aei%20testimony%20on%20replicator%20before%20citi%20subcommittee%20hasc%20v2.pdf.Greenwalt, W. C. DOD's Replicator Program: Challenges and Opportunities. House Armed Services Committee, Subcommittee on Cyber, Innovative Technologies, and Information Systems, 19 Oct. 2023, https://armedservices.house.gov/sites/evo-subsites/republicans-armedservices.house.gov/files/greenwalt%20aei%20testimony%20on%20replicator%20before%20citi%20subcommittee%20hasc%20v2.pdf.Greenwalt, W. C. DOD's Replicator Program: Challenges and Opportunities. https://armedservices.house.gov/sites/evo-subsites/republicans-armedservices.house.gov/files/greenwalt%20aei%20testimony%20on%20replicator%20before%20citi%20subcommittee%20hasc%20v2.pdf (2023).W. C. Greenwalt, “DOD's Replicator Program: Challenges and Opportunities”, House Armed Services Committee, Subcommittee on Cyber, Innovative Technologies, and Information Systems, Oct. 2023. [Online]. Available: https://armedservices.house.gov/sites/evo-subsites/republicans-armedservices.house.gov/files/greenwalt%20aei%20testimony%20on%20replicator%20before%20citi%20subcommittee%20hasc%20v2.pdf
- Heelan (2025). How I used o3 to find CVE-2025-37899, a remote zeroday vulnerability in the Linux kernel’s SMB implementation. Sean Heelan's Blog.Heelan. (2025, May 22). How I used o3 to find CVE-2025-37899, a remote zeroday vulnerability in the Linux kernel’s SMB implementation. Sean Heelan's Blog. https://sean.heelan.io/2025/05/22/how-i-used-o3-to-find-cve-2025-37899-a-remote-zeroday-vulnerability-in-the-linux-kernels-smb-implementationHeelan. 2025. “How I Used O3 to Find CVE-2025-37899, a Remote Zeroday Vulnerability in the Linux Kernel’s SMB Implementation”. Sean Heelan's Blog, May 22. https://sean.heelan.io/2025/05/22/how-i-used-o3-to-find-cve-2025-37899-a-remote-zeroday-vulnerability-in-the-linux-kernels-smb-implementation.Heelan. “How I Used O3 to Find CVE-2025-37899, a Remote Zeroday Vulnerability in the Linux Kernel’s SMB Implementation”. Sean Heelan's Blog, 22 May 2025, https://sean.heelan.io/2025/05/22/how-i-used-o3-to-find-cve-2025-37899-a-remote-zeroday-vulnerability-in-the-linux-kernels-smb-implementation.Heelan. How I used o3 to find CVE-2025-37899, a remote zeroday vulnerability in the Linux kernel’s SMB implementation. Sean Heelan's Blog https://sean.heelan.io/2025/05/22/how-i-used-o3-to-find-cve-2025-37899-a-remote-zeroday-vulnerability-in-the-linux-kernels-smb-implementation (2025).Heelan, “How I used o3 to find CVE-2025-37899, a remote zeroday vulnerability in the Linux kernel’s SMB implementation”, Sean Heelan's Blog. [Online]. Available: https://sean.heelan.io/2025/05/22/how-i-used-o3-to-find-cve-2025-37899-a-remote-zeroday-vulnerability-in-the-linux-kernels-smb-implementation
- Human Rights Watch (2024). Questions and Answers: Israeli Military’s Use of Digital Tools in Gaza. Human Rights Watch.Human Rights Watch. (2024, September 10). Questions and Answers: Israeli Military’s Use of Digital Tools in Gaza. Human Rights Watch. https://hrw.org/news/2024/09/10/questions-and-answers-israeli-militarys-use-digital-tools-gazaHuman Rights Watch. 2024. “Questions and Answers: Israeli Military’s Use of Digital Tools in Gaza”. Human Rights Watch, September 10. https://hrw.org/news/2024/09/10/questions-and-answers-israeli-militarys-use-digital-tools-gaza.Human Rights Watch. “Questions and Answers: Israeli Military’s Use of Digital Tools in Gaza”. Human Rights Watch, 10 Sept. 2024, https://hrw.org/news/2024/09/10/questions-and-answers-israeli-militarys-use-digital-tools-gaza.Human Rights Watch. Questions and Answers: Israeli Military’s Use of Digital Tools in Gaza. Human Rights Watch https://hrw.org/news/2024/09/10/questions-and-answers-israeli-militarys-use-digital-tools-gaza (2024).Human Rights Watch, “Questions and Answers: Israeli Military’s Use of Digital Tools in Gaza”, Human Rights Watch. [Online]. Available: https://hrw.org/news/2024/09/10/questions-and-answers-israeli-militarys-use-digital-tools-gaza
- HYAS (2023). Home. Silent Push.HYAS. (2023). Home. Silent Push. https://hyas.com/blog/blackmamba-using-ai-to-generate-polymorphic-malwareHYAS. 2023. “Home”. Silent Push. https://hyas.com/blog/blackmamba-using-ai-to-generate-polymorphic-malware.HYAS. “Home”. Silent Push, 2023, https://hyas.com/blog/blackmamba-using-ai-to-generate-polymorphic-malware.HYAS. Home. Silent Push https://hyas.com/blog/blackmamba-using-ai-to-generate-polymorphic-malware (2023).HYAS, “Home”, Silent Push. [Online]. Available: https://hyas.com/blog/blackmamba-using-ai-to-generate-polymorphic-malware
- Jonas B. Sandbrink (2023). Artificial intelligence and biological misuse: Differentiating risks of language models and biological design tools. arXiv.Jonas B. Sandbrink. (2023). Artificial intelligence and biological misuse: Differentiating risks of language models and biological design tools. In arXiv. https://arxiv.org/abs/2306.13952Jonas B. Sandbrink. 2023. “Artificial Intelligence and Biological Misuse: Differentiating Risks of Language Models and Biological Design Tools”. In arXiv. Preprint, June 24. https://arxiv.org/abs/2306.13952.Jonas B. Sandbrink. “Artificial Intelligence and Biological Misuse: Differentiating Risks of Language Models and Biological Design Tools”. arXiv, 24 June 2023, https://arxiv.org/abs/2306.13952.Jonas B. Sandbrink. Artificial intelligence and biological misuse: Differentiating risks of language models and biological design tools. arXiv Preprint at https://arxiv.org/abs/2306.13952 (2023).Jonas B. Sandbrink, “Artificial intelligence and biological misuse: Differentiating risks of language models and biological design tools”, Jun. 24, 2023. [Online]. Available: https://arxiv.org/abs/2306.13952
- King, J. & Meinhardt, C. (2024). Rethinking Privacy in the AI Era: Policy Provocations for a Data-Centric World.King, J., & Meinhardt, C. (2024). Rethinking Privacy in the AI Era: Policy Provocations for a Data-Centric World. Stanford Institute for Human-Centered Artificial Intelligence. https://hai.stanford.edu/sites/default/files/2024-02/White-Paper-Rethinking-Privacy-AI-Era.pdfKing, J., and C. Meinhardt. 2024. Rethinking Privacy in the AI Era: Policy Provocations for a Data-Centric World. Stanford Institute for Human-Centered Artificial Intelligence. https://hai.stanford.edu/sites/default/files/2024-02/White-Paper-Rethinking-Privacy-AI-Era.pdf.King, J., and C. Meinhardt. Rethinking Privacy in the AI Era: Policy Provocations for a Data-Centric World. Stanford Institute for Human-Centered Artificial Intelligence, Feb. 2024, https://hai.stanford.edu/sites/default/files/2024-02/White-Paper-Rethinking-Privacy-AI-Era.pdf.King, J. & Meinhardt, C. Rethinking Privacy in the AI Era: Policy Provocations for a Data-Centric World. https://hai.stanford.edu/sites/default/files/2024-02/White-Paper-Rethinking-Privacy-AI-Era.pdf (2024).J. King and C. Meinhardt, “Rethinking Privacy in the AI Era: Policy Provocations for a Data-Centric World”, Stanford Institute for Human-Centered Artificial Intelligence, Feb. 2024. [Online]. Available: https://hai.stanford.edu/sites/default/files/2024-02/White-Paper-Rethinking-Privacy-AI-Era.pdf
- Leahy et al. (2024). Understanding AI Extinction Risks.Leahy et al. (2024). Understanding AI Extinction Risks. https://thecompendium.aiLeahy et al. 2024. “Understanding AI Extinction Risks”. https://thecompendium.ai.Leahy et al. Understanding AI Extinction Risks. 2024, https://thecompendium.ai.Leahy et al. Understanding AI Extinction Risks. https://thecompendium.ai (2024).Leahy et al., “Understanding AI Extinction Risks”. [Online]. Available: https://thecompendium.ai
- Li, N. et al. (2024). The WMDP Benchmark: Measuring and Reducing Malicious Use With Unlearning. arXiv.Li, N., Pan, A., Gopal, A., Yue, S., Berrios, D., Gatti, A., Li, J. D., Dombrowski, A.-K., Goel, S., Phan, L., Mukobi, G., Helm-Burger, N., Lababidi, R., Justen, L., Liu, A. B., Chen, M., Barrass, I., Zhang, O., Zhu, X., … Hendrycks, D. (2024). The WMDP Benchmark: Measuring and Reducing Malicious Use With Unlearning. In arXiv. https://arxiv.org/abs/2403.03218Li, N., A. Pan, A. Gopal, et al. 2024. “The WMDP Benchmark: Measuring and Reducing Malicious Use With Unlearning”. In arXiv. Preprint, March 5. https://arxiv.org/abs/2403.03218.Li, N., et al. “The WMDP Benchmark: Measuring and Reducing Malicious Use With Unlearning”. arXiv, 5 Mar. 2024, https://arxiv.org/abs/2403.03218.Li, N. et al. The WMDP Benchmark: Measuring and Reducing Malicious Use With Unlearning. arXiv Preprint at https://arxiv.org/abs/2403.03218 (2024).N. Li et al., “The WMDP Benchmark: Measuring and Reducing Malicious Use With Unlearning”, Mar. 05, 2024. [Online]. Available: https://arxiv.org/abs/2403.03218
- Li, Q., Wang, W., Xu, C., Sun, Z. & Yang, M. (2022). Learning Disentangled Representation for One-shot Progressive Face Swapping. arXiv.Li, Q., Wang, W., Xu, C., Sun, Z., & Yang, M.-H. (2022). Learning Disentangled Representation for One-shot Progressive Face Swapping. In arXiv. https://arxiv.org/abs/2203.12985Li, Q., W. Wang, C. Xu, Z. Sun, and M.-H. Yang. 2022. “Learning Disentangled Representation for One-shot Progressive Face Swapping”. In arXiv. Preprint, March 24. https://arxiv.org/abs/2203.12985.Li, Q., et al. “Learning Disentangled Representation for One-shot Progressive Face Swapping”. arXiv, 24 Mar. 2022, https://arxiv.org/abs/2203.12985.Li, Q., Wang, W., Xu, C., Sun, Z. & Yang, M.-H. Learning Disentangled Representation for One-shot Progressive Face Swapping. arXiv Preprint at https://arxiv.org/abs/2203.12985 (2022).Q. Li, W. Wang, C. Xu, Z. Sun, and M.-H. Yang, “Learning Disentangled Representation for One-shot Progressive Face Swapping”, Mar. 24, 2022. [Online]. Available: https://arxiv.org/abs/2203.12985
- Liu, X., Xu, N., Chen, M. & Xiao, C. (2023). AutoDAN: Generating Stealthy Jailbreak Prompts on Aligned Large Language Models. arXiv.Liu, X., Xu, N., Chen, M., & Xiao, C. (2023). AutoDAN: Generating Stealthy Jailbreak Prompts on Aligned Large Language Models. In arXiv. https://arxiv.org/abs/2310.04451Liu, X., N. Xu, M. Chen, and C. Xiao. 2023. “AutoDAN: Generating Stealthy Jailbreak Prompts on Aligned Large Language Models”. In arXiv. Preprint, October 3. https://arxiv.org/abs/2310.04451.Liu, X., et al. “AutoDAN: Generating Stealthy Jailbreak Prompts on Aligned Large Language Models”. arXiv, 3 Oct. 2023, https://arxiv.org/abs/2310.04451.Liu, X., Xu, N., Chen, M. & Xiao, C. AutoDAN: Generating Stealthy Jailbreak Prompts on Aligned Large Language Models. arXiv Preprint at https://arxiv.org/abs/2310.04451 (2023).X. Liu, N. Xu, M. Chen, and C. Xiao, “AutoDAN: Generating Stealthy Jailbreak Prompts on Aligned Large Language Models”, Oct. 03, 2023. [Online]. Available: https://arxiv.org/abs/2310.04451
- Liu, Y., Jia, Y., Geng, R., Jia, J. & Gong, N. Z. (2023). Formalizing and Benchmarking Prompt Injection Attacks and Defenses. arXiv.Liu, Y., Jia, Y., Geng, R., Jia, J., & Gong, N. Z. (2023). Formalizing and Benchmarking Prompt Injection Attacks and Defenses. In arXiv. https://arxiv.org/abs/2310.12815Liu, Y., Y. Jia, R. Geng, J. Jia, and N. Z. Gong. 2023. “Formalizing and Benchmarking Prompt Injection Attacks and Defenses”. In arXiv. Preprint, October 19. https://arxiv.org/abs/2310.12815.Liu, Y., et al. “Formalizing and Benchmarking Prompt Injection Attacks and Defenses”. arXiv, 19 Oct. 2023, https://arxiv.org/abs/2310.12815.Liu, Y., Jia, Y., Geng, R., Jia, J. & Gong, N. Z. Formalizing and Benchmarking Prompt Injection Attacks and Defenses. arXiv Preprint at https://arxiv.org/abs/2310.12815 (2023).Y. Liu, Y. Jia, R. Geng, J. Jia, and N. Z. Gong, “Formalizing and Benchmarking Prompt Injection Attacks and Defenses”, Oct. 19, 2023. [Online]. Available: https://arxiv.org/abs/2310.12815
- Mouton et al. (2024). Could Artificial Intelligence Be Misused to Plan Biological Attacks?.Mouton et al. (2024). Could Artificial Intelligence Be Misused to Plan Biological Attacks?. Internet Archive (https://web.archive.org/web/20260903172105/https://www.rand.org/pubs/research_reports/RRA2977-1.html). https://rand.org/pubs/research_reports/RRA2977-1.htmlMouton et al. 2024. “Could Artificial Intelligence Be Misused to Plan Biological Attacks?”. Https://web.archive.org/web/20260903172105/https://www.rand.org/pubs/research_reports/RRA2977-1.html. Internet Archive. https://rand.org/pubs/research_reports/RRA2977-1.html.Mouton et al. Could Artificial Intelligence Be Misused to Plan Biological Attacks?. 2024, Internet Archive, https://web.archive.org/web/20260903172105/https://www.rand.org/pubs/research_reports/RRA2977-1.html, https://rand.org/pubs/research_reports/RRA2977-1.html.Mouton et al. Could Artificial Intelligence Be Misused to Plan Biological Attacks?. https://rand.org/pubs/research_reports/RRA2977-1.html (2024).Mouton et al., “Could Artificial Intelligence Be Misused to Plan Biological Attacks?”. Accessed: Sep. 03, 2026. [Online]. Available: https://rand.org/pubs/research_reports/RRA2977-1.html
- Nasr, M. et al. (2023). Scalable Extraction of Training Data from (Production) Language Models. arXiv.Nasr, M., Carlini, N., Hayase, J., Jagielski, M., Cooper, A. F., Ippolito, D., Choquette-Choo, C. A., Wallace, E., Tramèr, F., & Lee, K. (2023). Scalable Extraction of Training Data from (Production) Language Models. In arXiv. https://arxiv.org/abs/2311.17035Nasr, M., N. Carlini, J. Hayase, et al. 2023. “Scalable Extraction of Training Data from (Production) Language Models”. In arXiv. Preprint, November 28. https://arxiv.org/abs/2311.17035.Nasr, M., et al. “Scalable Extraction of Training Data from (Production) Language Models”. arXiv, 28 Nov. 2023, https://arxiv.org/abs/2311.17035.Nasr, M. et al. Scalable Extraction of Training Data from (Production) Language Models. arXiv Preprint at https://arxiv.org/abs/2311.17035 (2023).M. Nasr et al., “Scalable Extraction of Training Data from (Production) Language Models”, Nov. 28, 2023. [Online]. Available: https://arxiv.org/abs/2311.17035
- National Security Commission on Emerging Biotechnology (2024). White Paper 3: Risks of AIxBio.National Security Commission on Emerging Biotechnology. (2024). White Paper 3: Risks of AIxBio (NSCEB White Paper Series on AIxBio). National Security Commission on Emerging Biotechnology. https://biotech.senate.gov/wp-content/uploads/2024/01/NSCEB_AIxBio_WP3_Risks.pdfNational Security Commission on Emerging Biotechnology. 2024. White Paper 3: Risks of AIxBio. NSCEB White Paper Series on AIxBio. National Security Commission on Emerging Biotechnology. https://biotech.senate.gov/wp-content/uploads/2024/01/NSCEB_AIxBio_WP3_Risks.pdf.National Security Commission on Emerging Biotechnology. White Paper 3: Risks of AIxBio. National Security Commission on Emerging Biotechnology, Jan. 2024, https://biotech.senate.gov/wp-content/uploads/2024/01/NSCEB_AIxBio_WP3_Risks.pdf. NSCEB White Paper Series on AIxBio.National Security Commission on Emerging Biotechnology. White Paper 3: Risks of AIxBio. https://biotech.senate.gov/wp-content/uploads/2024/01/NSCEB_AIxBio_WP3_Risks.pdf (2024).National Security Commission on Emerging Biotechnology, “White Paper 3: Risks of AIxBio”, National Security Commission on Emerging Biotechnology, Jan. 2024. [Online]. Available: https://biotech.senate.gov/wp-content/uploads/2024/01/NSCEB_AIxBio_WP3_Risks.pdf
- Newman (2024). Cybersecurity and AI: The Evolving Security Landscape | CAIS. Center for AI Safety.Newman. (2024). Cybersecurity and AI: The Evolving Security Landscape | CAIS. Center for AI Safety. https://safe.ai/blog/cybersecurity-and-ai-the-evolving-security-landscapeNewman. 2024. “Cybersecurity and AI: The Evolving Security Landscape | CAIS”. Center for AI Safety. https://safe.ai/blog/cybersecurity-and-ai-the-evolving-security-landscape.Newman. “Cybersecurity and AI: The Evolving Security Landscape | CAIS”. Center for AI Safety, 2024, https://safe.ai/blog/cybersecurity-and-ai-the-evolving-security-landscape.Newman. Cybersecurity and AI: The Evolving Security Landscape | CAIS. Center for AI Safety https://safe.ai/blog/cybersecurity-and-ai-the-evolving-security-landscape (2024).Newman, “Cybersecurity and AI: The Evolving Security Landscape | CAIS”, Center for AI Safety. [Online]. Available: https://safe.ai/blog/cybersecurity-and-ai-the-evolving-security-landscape
- Nguyen, N., Chandrasegaran, K., Abdollahzadeh, M. & Cheung, N. (2023). Re-thinking Model Inversion Attacks Against Deep Neural Networks. arXiv.Nguyen, N.-B., Chandrasegaran, K., Abdollahzadeh, M., & Cheung, N.-M. (2023). Re-thinking Model Inversion Attacks Against Deep Neural Networks. In arXiv. https://arxiv.org/abs/2304.01669Nguyen, N.-B., K. Chandrasegaran, M. Abdollahzadeh, and N.-M. Cheung. 2023. “Re-thinking Model Inversion Attacks Against Deep Neural Networks”. In arXiv. Preprint, April 4. https://arxiv.org/abs/2304.01669.Nguyen, N.-B., et al. “Re-thinking Model Inversion Attacks Against Deep Neural Networks”. arXiv, 4 Apr. 2023, https://arxiv.org/abs/2304.01669.Nguyen, N.-B., Chandrasegaran, K., Abdollahzadeh, M. & Cheung, N.-M. Re-thinking Model Inversion Attacks Against Deep Neural Networks. arXiv Preprint at https://arxiv.org/abs/2304.01669 (2023).N.-B. Nguyen, K. Chandrasegaran, M. Abdollahzadeh, and N.-M. Cheung, “Re-thinking Model Inversion Attacks Against Deep Neural Networks”, Apr. 04, 2023. [Online]. Available: https://arxiv.org/abs/2304.01669
- OpenAI (2017). Attacking machine learning with adversarial examples.OpenAI. (2017). Attacking machine learning with adversarial examples. Internet Archive (https://web.archive.org/web/20240406184223/https://openai.com/research/attacking-machine-learning-with-adversarial-examples). https://openai.com/research/attacking-machine-learning-with-adversarial-examplesOpenAI. 2017. “Attacking Machine Learning with Adversarial Examples”. Https://web.archive.org/web/20240406184223/https://openai.com/research/attacking-machine-learning-with-adversarial-examples. Internet Archive. https://openai.com/research/attacking-machine-learning-with-adversarial-examples.OpenAI. Attacking Machine Learning with Adversarial Examples. 2017, Internet Archive, https://web.archive.org/web/20240406184223/https://openai.com/research/attacking-machine-learning-with-adversarial-examples, https://openai.com/research/attacking-machine-learning-with-adversarial-examples.OpenAI. Attacking machine learning with adversarial examples. https://openai.com/research/attacking-machine-learning-with-adversarial-examples (2017).OpenAI, “Attacking machine learning with adversarial examples”. Accessed: Apr. 06, 2024. [Online]. Available: https://openai.com/research/attacking-machine-learning-with-adversarial-examples
- Panel of Experts on Libya (2021). Letter, 8 Mar. 2021, from the Panel of Experts on Libya Established pursuant to Resolution 1973 (2011). United Nations Digital Library System.Panel of Experts on Libya. (2021). Letter, 8 Mar. 2021, from the Panel of Experts on Libya Established pursuant to Resolution 1973 (2011). Internet Archive (https://web.archive.org/web/20250702063934/https://digitallibrary.un.org/record/3905159?v=pdf). United Nations Digital Library System. https://www.digitallibrary.un.org/record/3905159?v=pdfPanel of Experts on Libya. 2021. “Letter, 8 Mar. 2021, from the Panel of Experts on Libya Established Pursuant to Resolution 1973 (2011)”. United Nations Digital Library System. Https://web.archive.org/web/20250702063934/https://digitallibrary.un.org/record/3905159?v=pdf. Internet Archive. https://www.digitallibrary.un.org/record/3905159?v=pdf.Panel of Experts on Libya. “Letter, 8 Mar. 2021, from the Panel of Experts on Libya Established Pursuant to Resolution 1973 (2011)”. United Nations Digital Library System, 2021, Internet Archive, https://web.archive.org/web/20250702063934/https://digitallibrary.un.org/record/3905159?v=pdf, https://www.digitallibrary.un.org/record/3905159?v=pdf.Panel of Experts on Libya. Letter, 8 Mar. 2021, from the Panel of Experts on Libya Established pursuant to Resolution 1973 (2011). United Nations Digital Library System https://www.digitallibrary.un.org/record/3905159?v=pdf (2021).Panel of Experts on Libya, “Letter, 8 Mar. 2021, from the Panel of Experts on Libya Established pursuant to Resolution 1973 (2011)”, United Nations Digital Library System. Accessed: Jul. 02, 2025. [Online]. Available: https://www.digitallibrary.un.org/record/3905159?v=pdf
- Pannu, J., Gebauer, S., McKelvey Jr, G., Cicero, A. & Inglesby, T. (2024). AI could pose pandemic-scale biosecurity risks. Here’s how to make it safer. Nature.Pannu, J., Gebauer, S., McKelvey Jr, G., Cicero, A., & Inglesby, T. (2024). AI could pose pandemic-scale biosecurity risks. Here’s how to make it safer. Nature. https://doi.org/10.1038/d41586-024-03815-2Pannu, J., S. Gebauer, G. McKelvey Jr, A. Cicero, and T. Inglesby. 2024. “AI Could Pose Pandemic-scale Biosecurity Risks. Here’s How to Make It Safer”. Nature, ahead of print, November 21. https://doi.org/10.1038/d41586-024-03815-2.Pannu, J., et al. “AI Could Pose Pandemic-scale Biosecurity Risks. Here’s How to Make It Safer”. Nature, Nov. 2024, https://doi.org/10.1038/d41586-024-03815-2.Pannu, J., Gebauer, S., McKelvey Jr, G., Cicero, A. & Inglesby, T. AI could pose pandemic-scale biosecurity risks. Here’s how to make it safer. Nature https://doi.org/10.1038/d41586-024-03815-2 (2024) doi:10.1038/d41586-024-03815-2.J. Pannu, S. Gebauer, G. McKelvey Jr, A. Cicero, and T. Inglesby, “AI could pose pandemic-scale biosecurity risks. Here’s how to make it safer”, Nature, Nov. 2024, doi: 10.1038/d41586-024-03815-2.
- Peppin et al. (2024). The Reality of AI and Biorisk. arXiv.org.Peppin et al. (2024). The Reality of AI and Biorisk. arXiv.org. https://www.arxiv.org/abs/2412.01946Peppin et al. 2024. “The Reality of AI and Biorisk”. arXiv.org. https://www.arxiv.org/abs/2412.01946.Peppin et al. “The Reality of AI and Biorisk”. arXiv.org, 2024, https://www.arxiv.org/abs/2412.01946.Peppin et al. The Reality of AI and Biorisk. arXiv.org https://www.arxiv.org/abs/2412.01946 (2024).Peppin et al., “The Reality of AI and Biorisk”, arXiv.org. [Online]. Available: https://www.arxiv.org/abs/2412.01946
- Policy-Relevant Science & Technology (2023). Munk Debate on Artificial Intelligence | Bengio & Tegmark vs. Mitchell & LeCun. YouTube.Policy-Relevant Science & Technology. (2023). Munk Debate on Artificial Intelligence | Bengio & Tegmark vs. Mitchell & LeCun [Video recording]. In YouTube. https://www.youtube.com/watch?v=144uOfr4SYAPolicy-Relevant Science & Technology. 2023. “Munk Debate on Artificial Intelligence | Bengio & Tegmark Vs. Mitchell & LeCun”. YouTube. https://www.youtube.com/watch?v=144uOfr4SYA.Policy-Relevant Science & Technology. “Munk Debate on Artificial Intelligence | Bengio & Tegmark Vs. Mitchell & LeCun”. YouTube, 2023, https://www.youtube.com/watch?v=144uOfr4SYA.Policy-Relevant Science & Technology. Munk Debate on Artificial Intelligence | Bengio & Tegmark Vs. Mitchell & LeCun. YouTube (2023).Policy-Relevant Science & Technology, Munk Debate on Artificial Intelligence | Bengio & Tegmark vs. Mitchell & LeCun, (2023). [Online Video]. Available: https://www.youtube.com/watch?v=144uOfr4SYA
- Qin, Z., Zhao, W., Yu, X. & Sun, X. (2023). OpenVoice: Versatile Instant Voice Cloning. arXiv.Qin, Z., Zhao, W., Yu, X., & Sun, X. (2023). OpenVoice: Versatile Instant Voice Cloning. In arXiv. https://arxiv.org/abs/2312.01479Qin, Z., W. Zhao, X. Yu, and X. Sun. 2023. “OpenVoice: Versatile Instant Voice Cloning”. In arXiv. Preprint, December 3. https://arxiv.org/abs/2312.01479.Qin, Z., et al. “OpenVoice: Versatile Instant Voice Cloning”. arXiv, 3 Dec. 2023, https://arxiv.org/abs/2312.01479.Qin, Z., Zhao, W., Yu, X. & Sun, X. OpenVoice: Versatile Instant Voice Cloning. arXiv Preprint at https://arxiv.org/abs/2312.01479 (2023).Z. Qin, W. Zhao, X. Yu, and X. Sun, “OpenVoice: Versatile Instant Voice Cloning”, Dec. 03, 2023. [Online]. Available: https://arxiv.org/abs/2312.01479
- Rivera, J., Mukobi, G., Reuel, A., Lamparth, M., Smith, C. & Schneider, J. (2024). Escalation Risks from Language Models in Military and Diplomatic Decision-Making. arXiv.Rivera, J.-P., Mukobi, G., Reuel, A., Lamparth, M., Smith, C., & Schneider, J. (2024). Escalation Risks from Language Models in Military and Diplomatic Decision-Making. In arXiv. https://doi.org/10.1145/3630106.3658942Rivera, J.-P., G. Mukobi, A. Reuel, M. Lamparth, C. Smith, and J. Schneider. 2024. “Escalation Risks from Language Models in Military and Diplomatic Decision-Making”. In arXiv. Preprint, January 7. https://doi.org/10.1145/3630106.3658942.Rivera, J.-P., et al. “Escalation Risks from Language Models in Military and Diplomatic Decision-Making”. arXiv, 7 Jan. 2024, https://doi.org/10.1145/3630106.3658942.Rivera, J.-P. et al. Escalation Risks from Language Models in Military and Diplomatic Decision-Making. arXiv Preprint at https://doi.org/10.1145/3630106.3658942 (2024).J.-P. Rivera, G. Mukobi, A. Reuel, M. Lamparth, C. Smith, and J. Schneider, “Escalation Risks from Language Models in Military and Diplomatic Decision-Making”, Jan. 07, 2024. doi: 10.1145/3630106.3658942.
- Sandoval-Segura, P., Singla, V., Geiping, J., Goldblum, M., Goldstein, T. & Jacobs, D. W. (2022). Autoregressive Perturbations for Data Poisoning. arXiv.Sandoval-Segura, P., Singla, V., Geiping, J., Goldblum, M., Goldstein, T., & Jacobs, D. W. (2022). Autoregressive Perturbations for Data Poisoning. In arXiv. https://arxiv.org/abs/2206.03693Sandoval-Segura, P., V. Singla, J. Geiping, M. Goldblum, T. Goldstein, and D. W. Jacobs. 2022. “Autoregressive Perturbations for Data Poisoning”. In arXiv. Preprint, June 8. https://arxiv.org/abs/2206.03693.Sandoval-Segura, P., et al. “Autoregressive Perturbations for Data Poisoning”. arXiv, 8 June 2022, https://arxiv.org/abs/2206.03693.Sandoval-Segura, P. et al. Autoregressive Perturbations for Data Poisoning. arXiv Preprint at https://arxiv.org/abs/2206.03693 (2022).P. Sandoval-Segura, V. Singla, J. Geiping, M. Goldblum, T. Goldstein, and D. W. Jacobs, “Autoregressive Perturbations for Data Poisoning”, Jun. 08, 2022. [Online]. Available: https://arxiv.org/abs/2206.03693
- Schwarzschild, A., Goldblum, M., Gupta, A., Dickerson, J. P. & Goldstein, T. (2020). Just How Toxic is Data Poisoning? A Unified Benchmark for Backdoor and Data Poisoning Attacks. arXiv.Schwarzschild, A., Goldblum, M., Gupta, A., Dickerson, J. P., & Goldstein, T. (2020). Just How Toxic is Data Poisoning? A Unified Benchmark for Backdoor and Data Poisoning Attacks. In arXiv. https://arxiv.org/abs/2006.12557Schwarzschild, A., M. Goldblum, A. Gupta, J. P. Dickerson, and T. Goldstein. 2020. “Just How Toxic Is Data Poisoning? A Unified Benchmark for Backdoor and Data Poisoning Attacks”. In arXiv. Preprint, June 22. https://arxiv.org/abs/2006.12557.Schwarzschild, A., et al. “Just How Toxic Is Data Poisoning? A Unified Benchmark for Backdoor and Data Poisoning Attacks”. arXiv, 22 June 2020, https://arxiv.org/abs/2006.12557.Schwarzschild, A., Goldblum, M., Gupta, A., Dickerson, J. P. & Goldstein, T. Just How Toxic is Data Poisoning? A Unified Benchmark for Backdoor and Data Poisoning Attacks. arXiv Preprint at https://arxiv.org/abs/2006.12557 (2020).A. Schwarzschild, M. Goldblum, A. Gupta, J. P. Dickerson, and T. Goldstein, “Just How Toxic is Data Poisoning? A Unified Benchmark for Backdoor and Data Poisoning Attacks”, Jun. 22, 2020. [Online]. Available: https://arxiv.org/abs/2006.12557
- Shayegani, E., Mamun, M. A. A., Fu, Y., Zaree, P., Dong, Y. & Abu-Ghazaleh, N. (2023). Survey of Vulnerabilities in Large Language Models Revealed by Adversarial Attacks. arXiv.Shayegani, E., Mamun, M. A. A., Fu, Y., Zaree, P., Dong, Y., & Abu-Ghazaleh, N. (2023). Survey of Vulnerabilities in Large Language Models Revealed by Adversarial Attacks. In arXiv. https://arxiv.org/abs/2310.10844Shayegani, E., M. A. A. Mamun, Y. Fu, P. Zaree, Y. Dong, and N. Abu-Ghazaleh. 2023. “Survey of Vulnerabilities in Large Language Models Revealed by Adversarial Attacks”. In arXiv. Preprint, October 16. https://arxiv.org/abs/2310.10844.Shayegani, E., et al. “Survey of Vulnerabilities in Large Language Models Revealed by Adversarial Attacks”. arXiv, 16 Oct. 2023, https://arxiv.org/abs/2310.10844.Shayegani, E. et al. Survey of Vulnerabilities in Large Language Models Revealed by Adversarial Attacks. arXiv Preprint at https://arxiv.org/abs/2310.10844 (2023).E. Shayegani, M. A. A. Mamun, Y. Fu, P. Zaree, Y. Dong, and N. Abu-Ghazaleh, “Survey of Vulnerabilities in Large Language Models Revealed by Adversarial Attacks”, Oct. 16, 2023. [Online]. Available: https://arxiv.org/abs/2310.10844
- Shokri, R., Stronati, M., Song, C. & Shmatikov, V. (2016). Membership Inference Attacks against Machine Learning Models. arXiv.Shokri, R., Stronati, M., Song, C., & Shmatikov, V. (2016). Membership Inference Attacks against Machine Learning Models. In arXiv. https://arxiv.org/abs/1610.05820Shokri, R., M. Stronati, C. Song, and V. Shmatikov. 2016. “Membership Inference Attacks Against Machine Learning Models”. In arXiv. Preprint, October 18. https://arxiv.org/abs/1610.05820.Shokri, R., et al. “Membership Inference Attacks Against Machine Learning Models”. arXiv, 18 Oct. 2016, https://arxiv.org/abs/1610.05820.Shokri, R., Stronati, M., Song, C. & Shmatikov, V. Membership Inference Attacks against Machine Learning Models. arXiv Preprint at https://arxiv.org/abs/1610.05820 (2016).R. Shokri, M. Stronati, C. Song, and V. Shmatikov, “Membership Inference Attacks against Machine Learning Models”, Oct. 18, 2016. [Online]. Available: https://arxiv.org/abs/1610.05820
- Simmons-Edler, R., Badman, R., Longpre, S. & Rajan, K. (2024). AI-Powered Autonomous Weapons Risk Geopolitical Instability and Threaten AI Research. arXiv.Simmons-Edler, R., Badman, R., Longpre, S., & Rajan, K. (2024). AI-Powered Autonomous Weapons Risk Geopolitical Instability and Threaten AI Research. In arXiv. https://arxiv.org/abs/2405.01859Simmons-Edler, R., R. Badman, S. Longpre, and K. Rajan. 2024. “AI-Powered Autonomous Weapons Risk Geopolitical Instability and Threaten AI Research”. In arXiv. Preprint, May 3. https://arxiv.org/abs/2405.01859.Simmons-Edler, R., et al. “AI-Powered Autonomous Weapons Risk Geopolitical Instability and Threaten AI Research”. arXiv, 3 May 2024, https://arxiv.org/abs/2405.01859.Simmons-Edler, R., Badman, R., Longpre, S. & Rajan, K. AI-Powered Autonomous Weapons Risk Geopolitical Instability and Threaten AI Research. arXiv Preprint at https://arxiv.org/abs/2405.01859 (2024).R. Simmons-Edler, R. Badman, S. Longpre, and K. Rajan, “AI-Powered Autonomous Weapons Risk Geopolitical Instability and Threaten AI Research”, May 03, 2024. [Online]. Available: https://arxiv.org/abs/2405.01859
- Slattery, P. et al. (2024). The AI risk repository: A meta-review, database, and taxonomy of risks from artificial intelligence. arXiv.Slattery, P., Saeri, A. K., Grundy, E. A. C., Graham, J., Noetel, M., Uuk, R., Dao, J., Pour, S., Casper, S., & Thompson, N. (2024). The AI risk repository: A meta-review, database, and taxonomy of risks from artificial intelligence. In arXiv. https://doi.org/10.1016/j.patter.2026.101517Slattery, P., A. K. Saeri, E. A. C. Grundy, et al. 2024. “The AI Risk Repository: A Meta-review, Database, and Taxonomy of Risks from Artificial Intelligence”. In arXiv. Preprint, August 14. https://doi.org/10.1016/j.patter.2026.101517.Slattery, P., et al. “The AI Risk Repository: A Meta-review, Database, and Taxonomy of Risks from Artificial Intelligence”. arXiv, 14 Aug. 2024, https://doi.org/10.1016/j.patter.2026.101517.Slattery, P. et al. The AI risk repository: A meta-review, database, and taxonomy of risks from artificial intelligence. arXiv Preprint at https://doi.org/10.1016/j.patter.2026.101517 (2024).P. Slattery et al., “The AI risk repository: A meta-review, database, and taxonomy of risks from artificial intelligence”, Aug. 14, 2024. doi: 10.1016/j.patter.2026.101517.
- The Bulletin (2024). MIT researchers ordered and combined parts of the 1918 pandemic influenza virus. Did they expose a security flaw?. Bulletin of the Atomic Scientists.The Bulletin. (2024, June 3). MIT researchers ordered and combined parts of the 1918 pandemic influenza virus. Did they expose a security flaw?. Bulletin of the Atomic Scientists. https://thebulletin.org/2024/06/mit-researchers-ordered-and-combined-parts-of-the-1918-pandemic-influenza-virus-did-they-expose-a-security-flawThe Bulletin. 2024. “MIT Researchers Ordered and Combined Parts of the 1918 Pandemic Influenza Virus. Did They Expose a Security Flaw?”. Bulletin of the Atomic Scientists, June 3. https://thebulletin.org/2024/06/mit-researchers-ordered-and-combined-parts-of-the-1918-pandemic-influenza-virus-did-they-expose-a-security-flaw.The Bulletin. “MIT Researchers Ordered and Combined Parts of the 1918 Pandemic Influenza Virus. Did They Expose a Security Flaw?”. Bulletin of the Atomic Scientists, 3 June 2024, https://thebulletin.org/2024/06/mit-researchers-ordered-and-combined-parts-of-the-1918-pandemic-influenza-virus-did-they-expose-a-security-flaw.The Bulletin. MIT researchers ordered and combined parts of the 1918 pandemic influenza virus. Did they expose a security flaw?. Bulletin of the Atomic Scientists https://thebulletin.org/2024/06/mit-researchers-ordered-and-combined-parts-of-the-1918-pandemic-influenza-virus-did-they-expose-a-security-flaw (2024).The Bulletin, “MIT researchers ordered and combined parts of the 1918 pandemic influenza virus. Did they expose a security flaw?”, Bulletin of the Atomic Scientists. [Online]. Available: https://thebulletin.org/2024/06/mit-researchers-ordered-and-combined-parts-of-the-1918-pandemic-influenza-virus-did-they-expose-a-security-flaw
- U.S Defense Innovation Unit (2023). The Replicator Initiative.U.S Defense Innovation Unit. (2023). The Replicator Initiative. Internet Archive (https://web.archive.org/web/20260303150022/https://www.diu.mil/replicator). https://diu.mil/replicatorU.S Defense Innovation Unit. 2023. “The Replicator Initiative”. Https://web.archive.org/web/20260303150022/https://www.diu.mil/replicator. Internet Archive. https://diu.mil/replicator.U.S Defense Innovation Unit. The Replicator Initiative. 2023, Internet Archive, https://web.archive.org/web/20260303150022/https://www.diu.mil/replicator, https://diu.mil/replicator.U.S Defense Innovation Unit. The Replicator Initiative. https://diu.mil/replicator (2023).U.S Defense Innovation Unit, “The Replicator Initiative”. Accessed: Mar. 03, 2026. [Online]. Available: https://diu.mil/replicator
- Urbina, F., Lentzos, F., Invernizzi, C. & Ekins, S. (2022). Dual use of artificial-intelligence-powered drug discovery. Nature Machine Intelligence.Urbina, F., Lentzos, F., Invernizzi, C., & Ekins, S. (2022). Dual use of artificial-intelligence-powered drug discovery. Nature Machine Intelligence. https://doi.org/10.1038/s42256-022-00465-9Urbina, F., F. Lentzos, C. Invernizzi, and S. Ekins. 2022. “Dual Use of Artificial-intelligence-powered Drug Discovery”. Nature Machine Intelligence, ahead of print, March 7. https://doi.org/10.1038/s42256-022-00465-9.Urbina, F., et al. “Dual Use of Artificial-intelligence-powered Drug Discovery”. Nature Machine Intelligence, Mar. 2022, https://doi.org/10.1038/s42256-022-00465-9.Urbina, F., Lentzos, F., Invernizzi, C. & Ekins, S. Dual use of artificial-intelligence-powered drug discovery. Nature Machine Intelligence https://doi.org/10.1038/s42256-022-00465-9 (2022) doi:10.1038/s42256-022-00465-9.F. Urbina, F. Lentzos, C. Invernizzi, and S. Ekins, “Dual use of artificial-intelligence-powered drug discovery”, Nature Machine Intelligence, Mar. 2022, doi: 10.1038/s42256-022-00465-9.
- Williams et al. (2025). Forecasting LLM-enabled Biorisk and the Efficacy of Safeguards. Forecasting Research Institute.Williams et al. (2025). Forecasting LLM-enabled Biorisk and the Efficacy of Safeguards. Forecasting Research Institute. https://forecastingresearch.org/ai-enabled-bioriskWilliams et al. 2025. “Forecasting LLM-enabled Biorisk and the Efficacy of Safeguards”. Forecasting Research Institute. https://forecastingresearch.org/ai-enabled-biorisk.Williams et al. “Forecasting LLM-enabled Biorisk and the Efficacy of Safeguards”. Forecasting Research Institute, 2025, https://forecastingresearch.org/ai-enabled-biorisk.Williams et al. Forecasting LLM-enabled Biorisk and the Efficacy of Safeguards. Forecasting Research Institute https://forecastingresearch.org/ai-enabled-biorisk (2025).Williams et al., “Forecasting LLM-enabled Biorisk and the Efficacy of Safeguards”, Forecasting Research Institute. [Online]. Available: https://forecastingresearch.org/ai-enabled-biorisk
- Xu, Y., Deng, B., Wang, J., Jing, Y., Pan, J. & He, S. (2022). High-resolution Face Swapping via Latent Semantics Disentanglement. arXiv.Xu, Y., Deng, B., Wang, J., Jing, Y., Pan, J., & He, S. (2022). High-resolution Face Swapping via Latent Semantics Disentanglement. In arXiv. https://arxiv.org/abs/2203.15958Xu, Y., B. Deng, J. Wang, Y. Jing, J. Pan, and S. He. 2022. “High-resolution Face Swapping via Latent Semantics Disentanglement”. In arXiv. Preprint, March 30. https://arxiv.org/abs/2203.15958.Xu, Y., et al. “High-resolution Face Swapping via Latent Semantics Disentanglement”. arXiv, 30 Mar. 2022, https://arxiv.org/abs/2203.15958.Xu, Y. et al. High-resolution Face Swapping via Latent Semantics Disentanglement. arXiv Preprint at https://arxiv.org/abs/2203.15958 (2022).Y. Xu, B. Deng, J. Wang, Y. Jing, J. Pan, and S. He, “High-resolution Face Swapping via Latent Semantics Disentanglement”, Mar. 30, 2022. [Online]. Available: https://arxiv.org/abs/2203.15958
- Zhang, G., Yan, C., Ji, X., Zhang, T., Zhang, T. & Xu, W. (2017). DolphinAtack: Inaudible Voice Commands. arXiv.Zhang, G., Yan, C., Ji, X., Zhang, T., Zhang, T., & Xu, W. (2017). DolphinAtack: Inaudible Voice Commands. In arXiv. https://doi.org/10.1145/3133956.3134052Zhang, G., C. Yan, X. Ji, T. Zhang, T. Zhang, and W. Xu. 2017. “DolphinAtack: Inaudible Voice Commands”. In arXiv. Preprint, August 31. https://doi.org/10.1145/3133956.3134052.Zhang, G., et al. “DolphinAtack: Inaudible Voice Commands”. arXiv, 31 Aug. 2017, https://doi.org/10.1145/3133956.3134052.Zhang, G. et al. DolphinAtack: Inaudible Voice Commands. arXiv Preprint at https://doi.org/10.1145/3133956.3134052 (2017).G. Zhang, C. Yan, X. Ji, T. Zhang, T. Zhang, and W. Xu, “DolphinAtack: Inaudible Voice Commands”, Aug. 31, 2017. doi: 10.1145/3133956.3134052.
- Zhao, M., Zhang, L., Ye, J., Lu, H., Yin, B. & Wang, X. (2024). Adversarial Training: A Survey. arXiv.Zhao, M., Zhang, L., Ye, J., Lu, H., Yin, B., & Wang, X. (2024). Adversarial Training: A Survey. In arXiv. https://arxiv.org/abs/2410.15042Zhao, M., L. Zhang, J. Ye, H. Lu, B. Yin, and X. Wang. 2024. “Adversarial Training: A Survey”. In arXiv. Preprint, October 19. https://arxiv.org/abs/2410.15042.Zhao, M., et al. “Adversarial Training: A Survey”. arXiv, 19 Oct. 2024, https://arxiv.org/abs/2410.15042.Zhao, M. et al. Adversarial Training: A Survey. arXiv Preprint at https://arxiv.org/abs/2410.15042 (2024).M. Zhao, L. Zhang, J. Ye, H. Lu, B. Yin, and X. Wang, “Adversarial Training: A Survey”, Oct. 19, 2024. [Online]. Available: https://arxiv.org/abs/2410.15042
- Zhu, Y., Li, Q., Wang, J., Xu, C. & Sun, Z. (2021). One Shot Face Swapping on Megapixels. arXiv.Zhu, Y., Li, Q., Wang, J., Xu, C., & Sun, Z. (2021). One Shot Face Swapping on Megapixels. In arXiv. https://arxiv.org/abs/2105.04932Zhu, Y., Q. Li, J. Wang, C. Xu, and Z. Sun. 2021. “One Shot Face Swapping on Megapixels”. In arXiv. Preprint, May 11. https://arxiv.org/abs/2105.04932.Zhu, Y., et al. “One Shot Face Swapping on Megapixels”. arXiv, 11 May 2021, https://arxiv.org/abs/2105.04932.Zhu, Y., Li, Q., Wang, J., Xu, C. & Sun, Z. One Shot Face Swapping on Megapixels. arXiv Preprint at https://arxiv.org/abs/2105.04932 (2021).Y. Zhu, Q. Li, J. Wang, C. Xu, and Z. Sun, “One Shot Face Swapping on Megapixels”, May 11, 2021. [Online]. Available: https://arxiv.org/abs/2105.04932
Was this section useful?
Thank you for your feedback
Your input helps improve the Atlas.