Concerns about generative AI by malicious users are growing, so Google announced an expansion of its Vulnerability Rewards Program (VRP), a bug bounty program of the company, to focus on attacks related to artificial intelligence. The company announced the new expansion and explained in detail which discoveries will be eligible for rewards and which will not fall within the scope. For example, a discovery of training data mining that exposes private, sensitive information falls within the scope ,but if only public, non-sensitive data is exposed, then it will not qualify for a reward.

Artificial intelligence has become a part of our daily lives, and it brings new challenges to cybersecurity. As Google explained, AI presents different security issues than other technologies and new guidance is needed. “We believe that expanding the VRP will incentivize research around security and uncover potential issues that will ultimately make AI safer for everyone,” the company said. “We are also expanding our open source security work to make information about AI supply chain security globally traceable and verifiable.”
See also: Google Search: “About this image” checks for AI misuse
Companies involved in products and services, including Google, gathered at the White House, pledging greater discovery and awareness of vulnerabilities in artificial intelligence. The expansion of Google's bug bounty program to include artificial intelligence (AI) comes ahead of an executive order from President Biden reportedly scheduled for Monday, October 30, that would create strict assessments and requirements for AI models to be used by government agencies.
See also: Nightshade “Data Poisoning Tool”: Protecting Images with AI

Bug bounty programs for attacks related to generative AI are useful because vulnerability hunters who focus on these types of attacks can discover and report issues that traditional vulnerability detection methods cannot detect. This can help Google and other companies improve the security of their systems and address potential threats from such attacks.
See also: Artificial intelligence (AI) and surveillance technology
However, there are also challenges that need to be addressed. Attacks related to generative AI are relatively new and complex, and detecting them can require specialized knowledge and tools. Vulnerability who focus on such attacks must be familiar with advanced techniques and have the necessary experience to address these challenges.
Source: https://www.engadget.com/
