BEGIN:VCALENDAR
VERSION:2.0
PRODID:-//wp-events-plugin.com//7.4.3//EN
TZID:America/Los_Angeles
X-WR-TIMEZONE:America/Los_Angeles
BEGIN:VEVENT
UID:0-1824@hmc.edu
DTSTART;TZID=America/Los_Angeles:20260925T110000
DTEND;TZID=America/Los_Angeles:20260925T120000
DTSTAMP:20260910T203440Z
URL:https://www.hmc.edu/calendar/events/cs-colloquium-from-prompts-to-sili
 con-security-and-privacy-threats-across-the-llm-stack-nael-abu-ghazaleh/
SUMMARY:CS Colloquium– “From Prompts to Silicon: Security and Privacy T
 hreats Across the LLM Stack\,” Nael Abu-Ghazaleh
DESCRIPTION:Large language models are now trusted with sensitive data\, emb
 edded in consequential decision pipelines\, and are hosted on shared\, exp
 ensive hardware. These factors make them an increasingly attractive target
 \, and not just at the level of what you type into a chat box. In this tal
 k\, we'll go on a tour of LLM security and privacy threats\, organized aro
 und a simple question\, looking at different classes of attacks based on a
 ttackers' access points.\n\nAbu-Ghazaleh starts where most people think LL
 M security lives: at the prompt itself\, showing how attackers with malici
 ous intent can bypass the model’s safety training. A second group of att
 acks targets training time\, where an attacker who controls even a small s
 lice of a model's training data can plant hidden behaviors that surface on
 ly later\, including those that enable leaking private information or unde
 rmining the safety alignment of the model. Finally\, Abu-Ghazaleh goes bel
 ow the model entirely\, to the hardware it runs on: his recent work shows 
 the GPU infrastructure powering today’s LLMs leaks information across us
 ers who are supposed to be strongly isolated from each other. Taken togeth
 er\, these attacks show that LLM security isn’t one problem but several\
 , spread across different layers of the stack\, including inference time\,
  training time\, and hardware and system vulnerabilities. Abu-Ghazaleh clo
 ses with where he thinks the most promising defenses lie\, and the open qu
 estions.\n\n[caption id="attachment_5771" align="alignright" width="200"] 
  [/caption]\nSpeaker\nNael Abu-Ghazaleh is a professor in the Computer Sc
 ience and Engineering Department at the University of California\, Riversi
 de. His research is in architecture and system security\, and security for
  emerging systems. He has published over 250 papers in these areas\, sever
 al of which have been recognized with best paper awards or nominations. Hi
 s offensive security research has resulted in the discovery of several new
  attacks on CPUs and GPUs that have been disclosed to companies including 
 Intel\, AMD\, ARM\, Apple\, Microsoft\, Google and Nvidia\, and resulted i
 n patches and modifications to products\, and coverage from technical news
  outlets. He is a member of the Micro Hall of Fame\, an ACM distinguished 
 member\, an IEEE distinguished speaker and an IEEE Computer Society Distin
 guished Contributor.
CATEGORIES:Faculty,Staff,Students
LOCATION:Galileo Hall\, 240 Platt Blvd.\, Claremont\, CA\, 91711\, United S
 tates
X-APPLE-STRUCTURED-LOCATION;VALUE=URI;X-ADDRESS=240 Platt Blvd.\, Claremont
 \, CA\, 91711\, United States;X-APPLE-RADIUS=100;X-TITLE=Galileo Hall:geo:
 0,0
END:VEVENT
BEGIN:VTIMEZONE
TZID:America/Los_Angeles
X-LIC-LOCATION:America/Los_Angeles
BEGIN:DAYLIGHT
DTSTART:20260308T030000
TZOFFSETFROM:-0800
TZOFFSETTO:-0700
TZNAME:PDT
END:DAYLIGHT
END:VTIMEZONE
END:VCALENDAR