Evidence receipt / evaluation
Published · transcript-backedIlia Shumailov: evaluation
4 Oct 2025 Machine Learning Street Talk AI Agents Can Code 10,000 Lines of Hacking Tools In Seconds - Dr. Ilia Shumailov (ex-GDM)
“Usually, when I tell it to people, they get a little bit triggered, especially if they come from a cryptographic community because they say what I'm proposing is a little bit crazy.”
Source trail
Everything needed to verify it.
- Speaker
- Ilia Shumailov
- Attribution
- Verified speaker
- Claim type
- evaluation
- Recorded
- 4 Oct 2025
- Publisher
- Machine Learning Street Talk
Transcript context
…MLST is supported by CyberFund. Link in the description. I'm Ilya. I spend my days staring at models and trying to make sure they do what you expect them to do. Most of the time, they don't do what you expect them to do. So we're trying to fix this. In my previous life, I was an academic, and I've basically been publishing in both security and machine learning. Then I joined DeepMind where I stayed for 2 years in the best machine learning security team, and now I left. I am very unemployed and I'm trying to build security tooling for the future to make sure that as we get Agencik fleets integrated into more and more use cases, we can actually tell what they're doing. We can impose constraints on them, and we can have confidence that tomorrow they're not gonna leak our private information, hack the boxes on which they're running, and and so on. I'll I'll I'll share a story of about a topic that I think is extremely exciting. Usually, when I tell it to people, they get a little bit triggered, especially if they come from a cryptographic community because they say what I'm proposing is a little bit crazy. Now we have machine learning models. We actually know what they do. We know how they think. We can check their state. They are kind of like a resettable human, if you will. Right? So suddenly, what I'm marking in this work is that, actually, trusted third parties can exist. And when you do have those trusted third parties, you suddenly don't need to rely on this very expensive and hard and cumbersome cryptographic utilities. Right? To give you a very simple example, we can consider a YAML millionaire problem. This is where I have some money, you have some money. We wanna find out who's richer, but we don't wanna share how much money we have. So in order to solve this in cryptography, we usually rely on very complex protocols, which are very expensive to run, especially if you increase the dimensionality. But with models, what we could have done instead is that we can say, oh, let's pick JAMA as an example of a model. Let's both of us agree on a prompt. Say, you'll receive 2 numbers, number 1, number 2. The type annotations on them is integers. We will receive 2 integers. Say first if the first number is bigger. Otherwise, say second. And then the only 2 outputs the model can. We both agree. It can produce as first, the second, and then that is it. We just run inference. Maybe on a platform that can give you an integrity verification that the model exactly ran with the exact parameters and also the inputs we provided. And in this setting, you no longer need cryptography, and clearly, you will get the result you want, especially since you can trust this model to perform this trusted computation. And this trust model in itself is very different from any notion of trust you can find in cryptographic literature or in, like, more trust execution environment sort of literature. rusted computation. And this trust model in itself is very different from any notion of trust you can find in cryptographic literature or in, like, more trust execution environment sort of literature. And the overall argument is that maybe machine learning is actually going to change quite a bit in the way we approach those trusted computations in the future. Obviously, it's unreliable. Obviously, you don't get soundness completeness properties out of this. This is not a 0 knowledge proof. This is not an MPC protocol. This is not a trust execution environment. It's a completely different new way to approach private inference that truly, really exists because we have those trusted third parties to which we can give secrets. And as long as some conditions are certified, and you should read the article about them, you get significantly more out of them.…
Stored transcript either side of the excerpt. The highlighted words are the published quote; the surrounding text is unedited source, never generated.