Government
We owe the Trump admin a debt of gratitude for the Signal group chat leak
Sometimes journalists befuddle me, and I'm a journalist – although my touchy detractors would dispute that. Perhaps like you, I have been watching – with a healthy dose of bemusement and amusement – the outrage-du-jour dominate the latest 24-hour "news cycle" in North America and beyond. Such is the squirrel-like attention span of many of my perpetually outraged colleagues, that today's outrage usually has a short life expectancy since another outrage inevitably comes along tomorrow. But the outrage seizing Washington, DC – the capital of outrage – appears poised to consume the Beltway press corps for more than a day or two. When that happens, the outrage tends to evolve into a four-alarm scandal which journalists crave because it often translates into a big, ego-boosting award for the lucky scribe who triggered the original outrage.
The AI Hype Index: DeepSeek mania, Israel's spying tool, and cheating at chess
That's why we've created the AI Hype Index--a simple, at-a-glance summary of everything you need to know about the state of the industry. While AI models are certainly capable of creating interesting and sometimes entertaining material, their output isn't necessarily useful. Google DeepMind is hoping that its new robotics model could make machines more receptive to verbal commands, paving the way for us to simply speak orders to them aloud. Elsewhere, the Chinese startup Monica has created Manus, which it claims is the very first general AI agent to complete truly useful tasks. And burnt-out coders are allowing AI to take the wheel entirely in a new practice dubbed "vibe coding."
Foreign nationals flying drones over US military sites raises 'espionage' concern: expert
Federal officials face a looming threat of foreign nationals utilizing drones to surveil United States military bases after two recent arrests and a string of mysterious incursions suggest the country's airspace is ill-equipped to handle the rapidly evolving technology. In late 2024, the Department of Justice announced charges against Yinpiao Zhou, 39, for allegedly flying a drone over Vandenberg Space Force Base in California and taking photos of the facility. The Chinese-American citizen was detained as he attempted to board a China-bound flight and was charged with violation of national defense airspace and failure to register an aircraft. "Anyone operating a drone over a restricted space, like a military base, would be subject to prosecution," Ken Gray, a former FBI agent and military analyst, told Fox News Digital. "A foreign national operating [a drone] raises a concern about that person being involved in some type of espionage or intelligence gathering."
Government AI roll-outs threatened by outdated IT systems
The government's ambition to boost efficiency by embedding AI in all aspects of its work risks being undermined by out-of-date technology, poor quality data and a lack of skilled staff, an influential Commons committee has warned. The report by the cross-party public accounts committee (PAC) found that more than 20 government IT systems identified as "legacy", meaning out of date and unsupported, have yet to be given funding to improve them. Government research cited by the PAC in the report found that almost a third of central government IT systems met this definition in 2024. Keir Starmer's government has repeatedly stressed its desire to increase economic growth through the mass take-up of AI systems, including in the public sector. An official plan for the technology published in January called for the government to "rapidly pilot" AI-powered services, saying this would both increase productivity and improve people's experience of dealing with officialdom.
A Methodology to extract Geo-Referenced Standard Routes from AIS Data
Corvino, Michela, Daffinà, Filippo, Francalanci, Chiara, Giacomazzi, Paolo, Magliani, Martina, Ravanelli, Paolo, Stahl, Torbjorn
Maritime AIS (Automatic Identification Systems) data serve as a valuable resource for studying vessel behavior. This study proposes a methodology to analyze route between maritime points of interest and extract geo-referenced standard routes, as maritime patterns of life, from raw AIS data. The underlying assumption is that ships adhere to consistent patterns when travelling in certain maritime areas due to geographical, environmental, or economic factors. Deviations from these patterns may be attributed to weather conditions, seasonality, or illicit activities. This enables maritime surveillance authorities to analyze the navigational behavior between ports, providing insights on vessel route patterns, possibly categorized by vessel characteristics (type, flag, or size). Our methodological process begins by segmenting AIS data into distinct routes using a finite state machine (FSM), which describes routes as seg-ments connecting pairs of points of interest. The extracted segments are ag-gregated based on their departure and destination ports and then modelled using iterative density-based clustering to connect these ports. The cluster-ing parameters are assigned manually to sample and then extended to the en-tire dataset using linear regression. Overall, the approach proposed in this paper is unsupervised and does not require any ground truth to be trained. The approach has been tested on data on the on a six-year AIS dataset cover-ing the Arctic region and the Europe, Middle East, North Africa areas. The total size of our dataset is 1.15 Tbytes. The approach has proved effective in extracting standard routes, with less than 5% outliers, mostly due to routes with either their departure or their destination port not included in the test areas.
Three Kinds of AI Ethics
There is an overwhelming abundance of works in AI Ethics. This growth is chaotic because of how sudden it is, its volume, and its multidisciplinary nature. This makes difficult to keep track of debates, and to systematically characterize goals, research questions, methods, and expertise required by AI ethicists. In this article, I show that the relation between AI and ethics can be characterized in at least three ways, which correspond to three well-represented kinds of AI ethics: ethics and AI; ethics in AI; ethics of AI. I elucidate the features of these three kinds of AI Ethics, characterize their research questions, and identify the kind of expertise that each kind needs. I also show how certain criticisms to AI ethics are misplaced, as being done from the point of view of one kind of AI ethics, to another kind with different goals. All in all, this work sheds light on the nature of AI ethics, and sets the groundwork for more informed discussions about the scope, methods, and training of AI ethicists.
The Backfiring Effect of Weak AI Safety Regulation
Laufer, Benjamin, Kleinberg, Jon, Heidari, Hoda
Recent policy proposals aim to improve the safety of general-purpose AI, but there is little understanding of the efficacy of different regulatory approaches to AI safety. We present a strategic model that explores the interactions between the regulator, the general-purpose AI technology creators, and domain specialists--those who adapt the AI for specific applications. Our analysis examines how different regulatory measures, targeting different parts of the development chain, affect the outcome of the development process. In particular, we assume AI technology is described by two key attributes: safety and performance. The regulator first sets a minimum safety standard that applies to one or both players, with strict penalties for non-compliance. The general-purpose creator then develops the technology, establishing its initial safety and performance levels. Next, domain specialists refine the AI for their specific use cases, and the resulting revenue is distributed between the specialist and generalist through an ex-ante bargaining process. Our analysis of this game reveals two key insights: First, weak safety regulation imposed only on the domain specialists can backfire. While it might seem logical to regulate use cases (as opposed to the general-purpose technology), our analysis shows that weak regulations targeting domain specialists alone can unintentionally reduce safety. This effect persists across a wide range of settings. Second, in sharp contrast to the previous finding, we observe that stronger, well-placed regulation can in fact benefit all players subjected to it. When regulators impose appropriate safety standards on both AI creators and domain specialists, the regulation functions as a commitment mechanism, leading to safety and performance gains, surpassing what is achieved under no regulation or regulating one player only.
Generating Synthetic Data with Formal Privacy Guarantees: State of the Art and the Road Ahead
Schlegel, Viktor, Bharath, Anil A, Zhao, Zilong, Yee, Kevin
Privacy-preserving synthetic data offers a promising solution to harness segregated data in high-stakes domains where information is compartmentalized for regulatory, privacy, or institutional reasons. This survey provides a comprehensive framework for understanding the landscape of privacy-preserving synthetic data, presenting the theoretical foundations of generative models and differential privacy followed by a review of state-of-the-art methods across tabular data, images, and text. Our synthesis of evaluation approaches highlights the fundamental trade-off between utility for down-stream tasks and privacy guarantees, while identifying critical research gaps: the lack of realistic benchmarks representing specialized domains and insufficient empirical evaluations required to contextualise formal guarantees. Through empirical analysis of four leading methods on five real-world datasets from specialized domains, we demonstrate significant performance degradation under realistic privacy constraints ($\epsilon \leq 4$), revealing a substantial gap between results reported on general domain benchmarks and performance on domain-specific data. %Our findings highlight key challenges including unaccounted privacy leakage, insufficient empirical verification of formal guarantees, and a critical deficit of realistic benchmarks. These challenges underscore the need for robust evaluation frameworks, standardized benchmarks for specialized domains, and improved techniques to address the unique requirements of privacy-sensitive fields such that this technology can deliver on its considerable potential.
Advancing Vulnerability Classification with BERT: A Multi-Objective Learning Model
--The rapid increase in cybersecurity vulnerabilities necessitates automated tools for analyzing and classifying vulnerability reports. This paper presents a novel V ulnerability Report Classifier that leverages the BERT (Bidirectional Encoder Representations from Transformers) model to perform multi-label classification of Common V ulnerabilities and Exposures (CVE) reports from the National V ulnerability Database (NVD). The classifier predicts both the severity (Low, Medium, High, Critical) and vulnerability types (e.g., Buffer Overflow, XSS) from textual descriptions. We introduce a custom training pipeline using a combined loss function--Cross-Entropy for severity and Binary Cross-Entropy with Logits for types--integrated into a Hugging Face Trainer subclass. Experiments on recent NVD data demonstrate promising results, with decreasing evaluation loss across epochs. The system is deployed via a REST API and a Streamlit UI, enabling real-time vulnerability analysis. This work contributes a scalable, open-source solution for cybersecurity practitioners to automate vulnerability triage. I NTRODUCTION The relentless evolution of software systems, driven by their increasing complexity and interconnectedness, has ushered in a dramatic rise in cybersecurity vulnerabilities, presenting a formidable challenge to organizations, governments, and individual users alike. Each year, thousands of new vulnerabilities are identified and cataloged, with repositories like the National Vulnerability Database (NVD) serving as critical resources for tracking these threats.
Enabling Heterogeneous Adversarial Transferability via Feature Permutation Attacks
Adversarial attacks in black-box settings are highly practical, with transfer-based attacks being the most effective at generating adversarial examples (AEs) that transfer from surrogate models to unseen target models. However, their performance significantly degrades when transferring across heterogeneous architectures -- such as CNNs, MLPs, and Vision Transformers (ViTs) -- due to fundamental architectural differences. To address this, we propose Feature Permutation Attack (FPA), a zero-FLOP, parameter-free method that enhances adversarial transferability across diverse architectures. FPA introduces a novel feature permutation (FP) operation, which rearranges pixel values in selected feature maps to simulate long-range dependencies, effectively making CNNs behave more like ViTs and MLPs. This enhances feature diversity and improves transferability both across heterogeneous architectures and within homogeneous CNNs. Extensive evaluations on 14 state-of-the-art architectures show that FPA achieves maximum absolute gains in attack success rates of 7.68% on CNNs, 14.57% on ViTs, and 14.48% on MLPs, outperforming existing black-box attacks. Additionally, FPA is highly generalizable and can seamlessly integrate with other transfer-based attacks to further boost their performance. Our findings establish FPA as a robust, efficient, and computationally lightweight strategy for enhancing adversarial transferability across heterogeneous architectures.