1 198
Suscriptores
Sin datos24 horas
+157 días
+4330 días
Archivo de publicaciones
1 198
Repost from AISecHub
AI landscape evolves, we’re seeing a decisive shift away from general-purpose intelligence toward 𝘀𝗽𝗲𝗰𝗶𝗮𝗹𝗶𝘇𝗲𝗱, 𝗱𝗼𝗺𝗮𝗶𝗻-𝗼𝗽𝘁𝗶𝗺𝗶𝘇𝗲𝗱 𝗺𝗼𝗱𝗲𝗹𝘀—each engineered to perform a specific role in an increasingly modular ecosystem.
Here’s a breakdown of what these eight models are, why they matter, and where
➦ LLM – Large Language Model
Purpose: General-purpose natural language understanding and generation
Architecture: Tokenization → Embedding → Transformer → Output
Use Cases: LLMs serve as the “default brain” for text-based tasks. But they often lack efficiency and adaptability for real-world environments.
➦ LCM – Language Compression Model
Purpose: Efficient language representation using compressed signal structures
Architecture: Sentence Segmentation → SONAR Embedding → Diffusion → Quantization → Output
Use Cases: LCMs make AI more accessible on low-resource devices by shrinking model size and maintaining semantic richness.
➦ LAM – Language-Action Model
Purpose: Transform high-level intent into executable tasks
Architecture: Input Processing → Perception → Intent Recognition → Task Breakdown → Action Planning & Execution
Use Cases: LAMs are foundational to agentic AI—moving from passive response to active reasoning, planning, and doing.
➦ MoE – Mixture of Experts
Purpose: Scalable inference by activating only the most relevant parts of the model. Architecture: Router → Expert Selection → Weighted Output
Use Cases: MoE models are like intelligent switchboards—activating just the “experts” needed for each input, reducing compute costs while maintaining accuracy.
➦ VLM – Vision-Language Model
Purpose: Joint understanding of visual and textual information
Architecture: Image Encoder + Text Encoder → Projection → Multimodal Processor → Language Model
Use Cases: VLMs are crucial for bridging modalities, enabling AI systems that “see and talk” at the same time.
➦ SLM – Small Language Model
Purpose: Deployable NLP in constrained environments
Architecture: Compact Optimization → Embedding → Quantization → Lightweight Transformer
Use Cases: SLMs prioritize speed, privacy, and cost, perfect for edge AI and enterprise deployments that don’t need full-scale LLMs.
➦ MLM – Masked Language Model
Purpose: Deep contextual understanding via bidirectional attention
Architecture: Token Masking → Embedding Layer → Left + Right Context → Prediction
Use Cases: MLMs learn to understand what’s 𝘮𝘪𝘴𝘴𝘪𝘯𝘨, which makes them exceptional for comprehension, correction, and fact completion.
➦ SAM – Segment Anything Model
Purpose: Universal image segmentation with minimal prompting. Architecture: Prompt Encoder + Image Encoder → Feature Correlation → Mask Decoder
Use Cases: SAMs bring a “zero-shot” capability to computer vision—point to anything, and the model can isolate it accurately. No retraining required.
1 198
Repost from AISecHub
C𝗼𝗺𝗺𝗼𝗻 𝗔𝗜 𝗮𝗴𝗲𝗻𝘁 𝘂𝘀𝗲 𝗰𝗮𝘀𝗲𝘀 𝗶𝗻 2025
𝗔𝗴𝗲𝗻𝘁𝗶𝗰 𝗥𝗔𝗚:
Retrieval-Augmented Generation reimagined. These agents don’t just retrieve knowledge — they evaluate sources, reason over them, and produce contextually grounded answers.
Used for internal knowledge assistants, intelligent documentation, and enterprise Q&A.
Examples: IBM watsonx, Perplexity AI, Glean etc.
𝗪𝗼𝗿𝗸𝗳𝗹𝗼𝘄 𝗔𝘂𝘁𝗼𝗺𝗮𝘁𝗶𝗼𝗻 𝗔𝗴𝗲𝗻𝘁𝘀:
These agents orchestrate tasks across systems. Triggered by APIs, UI actions, or internal events, they can perform multi-step processes without human involvement. Think automated onboarding flows, approvals, or back-office operations. Very easy to build for everybody.
Examples: Make.com, Flowise, n8n, Relevance AI etc.
𝗖𝗼𝗱𝗶𝗻𝗴 𝗔𝗴𝗲𝗻𝘁𝘀:
AI-powered development assistants that go beyond code suggestions. These agents can plan, refactor, debug, and even reason across repositories. Ideal for accelerating software engineering teams or bootstrapping prototypes.
Examples: Cursor, Roo Code, Windsurf etc.
𝗧𝗼𝗼𝗹-𝗕𝗮𝘀𝗲𝗱 𝗔𝗴𝗲𝗻𝘁𝘀:
Niche, high-utility agents designed to perform well-defined tasks with specific tools — from sending emails to querying internal search engines. These agents are easy to deploy and integrate into targeted workflows.
Examples: Breeze, Clay etc.
𝗖𝗼𝗺𝗽𝘂𝘁𝗲𝗿 𝗨𝘀𝗲 𝗔𝗴𝗲𝗻𝘁𝘀:
The most ambitious — and most misunderstood. These agents don’t just call APIs. They use the UI. Navigating browsers. Typing into forms. Clicking buttons. Agents that act like humans, powered by models like Claude and GPT-4.
𝗩𝗼𝗶𝗰𝗲 𝗔𝗴𝗲𝗻𝘁𝘀:
Where GenAI meets the phone line. These agents handle support calls, internal queries, and sales outreach... all with voice. Examples: ElevenLabs, Vapi, and others etc.
1 198
Repost from Not Boring Tech
📒 Hugging Face запустил официальный курс по MCP — в нём по полочкам разложили самую хайповую тему в нейронках прямо сейчас! Он за пару вечеров превратит вас из новичка в гуру.
Вы поймёте всю архитектуру MCP-серверов, научитесь пользоваться ими на практике и даже разработаете свои MCP-приложения. После прохождения курса выдают сертификат, который можно добавить в портфолио.
Сохраняем на выходные — тут.
@notboring_tech
1 198
Repost from AISecHub
Open Challenges in Multi-Agent Security: Towards Secure Systems of Interacting AI Agents
1 198
Встретились как-то два Дяди поболтать за жизнь LLM и GuardRails
Валера тут конечно в лице девушки, а Дядя как всегда брутален!
Посидели тут и послушали разговор еще раз и наконец-то открыли notebooklm.
И сделали вот такую красоту, для вас, чтобы вы тоже могли послушать.
Еще лайфхак как делать тайминги).
00:00 - Введение: безопасность и надежность LLM
00:29 - Входной контроль (фильтры, списки, BERT-классификаторы)
00:52 - Умные отказы вместо блокировок для поддержания UX
01:20 - Выходной контроль генерируемого контента
01:26 - Alignment (тонкая настройка модели)
01:45 - Стратегии: Alignment vs внешние фильтры
02:13 - Метрики: FPR и F1 score
02:32 - Проблема галлюцинаций в RAG
02:49 - "Размытие + быстрая проверка" для борьбы с галлюцинациями
03:28 - Малые модели (TinyBERT) для быстрой классификации
03:41 - Имитация обдумывания для естественности
03:55 - Тюнинг эмбеддеров (BERT, E5, BGE)
04:28 - Токен хилинг: предсказание и откат проблемных токенов
05:01 - Резюме: комплексный подход к надежности
05:29 - Вопрос о "разумности" vs хорошей инфраструктуре
Upd. Залили mp3, яблочники ликуйте и слушайте.
1 198
Встретились как-то два Дяди поболтать за жизнь LLM и GuardRails
Валера тут конечно в лице девушки, а Дядя как всегда брутален!
Посидели тут и послушали разговор еще раз и наконец-то открыли notebooklm.
И сделали вот такую красоту, для вас, чтобы вы тоже могли послушать.
Еще лайфхак как делать тайминги).
00:00 - Введение: безопасность и надежность LLM
00:29 - Входной контроль (фильтры, списки, BERT-классификаторы)
00:52 - Умные отказы вместо блокировок для поддержания UX
01:20 - Выходной контроль генерируемого контента
01:26 - Alignment (тонкая настройка модели)
01:45 - Стратегии: Alignment vs внешние фильтры
02:13 - Метрики: FPR и F1 score
02:32 - Проблема галлюцинаций в RAG
02:49 - "Размытие + быстрая проверка" для борьбы с галлюцинациями
03:28 - Малые модели (TinyBERT) для быстрой классификации
03:41 - Имитация обдумывания для естественности
03:55 - Тюнинг эмбеддеров (BERT, E5, BGE)
04:28 - Токен хилинг: предсказание и откат проблемных токенов
05:01 - Резюме: комплексный подход к надежности
05:29 - Вопрос о "разумности" vs хорошей инфраструктуре
Upd. Залили mp3, яблочники ликуйте и слушайте.
1 198
Governance — the framework’s first domain — is based on an organization’s approach to strategic planning of AI and in providing oversight and monitoring over how AI is planned, managed, and executed by management. The governing body relies upon information that is provided to them by the internal audit function . Internal auditors should strive to develop a trusted advisor relationship with governing bodies such as the audit committee, board, or equivalent governing body, and this relationship should include emerging topics such as AI that presents new oversight challenges .
The framework’s Management domain outlines an approach that the organization would use when planning and executing AI within the organization. The internal control environment surrounding AI is established by management in the “First Line” It also includes strategic aspects such as setting goals and objectives related to the overall AI strategic plan. Internal audit must ensure it understands the strategic direction of AI for the organization, and management’s approach for managing AI.
The framework’s Management domain also contains “Second Line” monitoring aspects of AI, such as what aspects enterprise risk management should consider when monitoring the “First Line .” Internal audit is often expected to participate in an organization’s risk assessment process. This domain will be relevant to internal audit as it maintains knowledge of AI-related risks.
The framework’s third domain, Internal Audit, includes aspects of both advisory activities to management and in providing assurance services in an audit capacity (“Third Line”). Internal audit can utilize the framework as a starting point in both roles when tasked with participating in AI assignments
1 198
Два определения агентов из статей 2023 года, в которых описываются агенты: LLM-агенты для планирования задач и использования инструментов (TPTU) и агенты когнитивной архитектуры (CoALA).
CoALA определяет "языковых агентов" как "систему искусственного интеллекта, которая использует LLM для взаимодействия с миром".
TPTU: агент - это "программа, использующая методы искусственного интеллекта для выполнения задач, которые обычно требуют человекоподобного интеллекта"
1 198
Repost from AISecHub
The Vulnerable MCP Project
A community-maintained database of known vulnerabilities, limitations, and security concerns with the Model Context Protocol (MCP)
vulnerablemcp.info
1 198
Repost from Security Harvester
I built Mithra: a security scanner for LLM-integrated APIs (detects prompt injection, DAN..)
https://mithrasec.com:
1. It detects risks unique to AI-enabled APIs—such as prompt injection, context bleeding, over-permissive output, and misuse potential—before attackers exploit them.
2. Finds vulnerabilities where user input may alter LLM behavior, responses, or access control logic.
3. Get your AI Vulnerability Database Taxonomy (AVID) and OWASP Top 10 for Large Language Model Applications report in minutes.
@secharvester
1 198
Repost from AISecHub
Agent Name Service (ANS) for Secure Al Agent Discovery
The Agent Name Service (ANS), developed under the OWASP GenAI Security Project – Agentic Security Initiative, introduces a secure, DNS-inspired framework for AI agent discovery. ANS leverages Public Key Infrastructure (PKI) for identity verification, structured JSON schemas for communication, and a protocol adapter layer supporting A2A, MCP, and ACP protocols.
The architecture defines a comprehensive naming structure (ANSName) that encodes protocol, agent capability, provider, and version metadata, enabling consistent, secure resolution across diverse agent networks. Security measures include PKI-backed identity verification, digital signatures, and Zero-Knowledge Proofs (ZKP) for capability validation.
1 198
Repost from CodeCamp
Полезное: нашёл библиотеку с 60+ сайд-проектами по нейросетям. Внутри гайды, по которым вы научитесь делать ИИ-агентов, RAG, поднимать MCP сервера и файн-тюнить модели.
У проектов разный уровень сложности, есть видео-туторы и весь нужный код — идеально для тренировки навыков.
Это бесплатно, забираем
1 198
Repost from DeepSchool
Как обучить текстовый эмбеддер на домен?
Представьте: перед вами, как перед ML-инженером, стоит задача — нарастить качество в некотором сервисе. У вас есть доступ к текстовым данным в домене решаемой задачи, а аналитики собрали вам разметку. Вы взяли любимую BERT-like модель, которую всегда использовали, завели обучение и уже потираете руки в ожидании хорошей оценки на ревью, но… Качество на тесте не растёт. Вы крутите параметры, а ничего не помогает.
Решить эту проблему вам поможет наша статья по обучению текстового эмбеддера под домен.
В этой статье мы разберём последовательность действий, которую стоит предпринимать при обучении текстового эмбеддера на домен, узнаем, как обернуть специфику задачи вам на пользу и всё-таки нарастить конечное качество. Подробнее остановимся на этапе предобучения, рассмотрим RetroMAE, модификацию MLM для retrieval-моделей и контрастное обучение с InfoNCE, основной подход к улучшению семантики представлений в области.
Читайте новую статью по ссылке
1 198
Построение AI-ассистента для работы с TI-знаниями
Крутейший доклад Коли Арефьева на https://linkmeetup.ru/msk25doklady
Каждый день в мире появляются десятки киберугроз, требующих анализа и оперативного реагирования. За год число тактических и оперативных TI отчетов превышает 4000. Анализ столь большого объема информации требует значительных ресурсов, в том числе крупных команд TI-аналитиков.
AI-ассистент на основе LLM и RAG может стать полноценным интерфейсом между аналитиками и обширной базой внешних TI-знаний. В рамках доклада я расскажу общую теорию построения мульти-агентских AI-ассистентов, упрощающих работу с огромным массивом TI-знаний.
