joshuark quotes a report from MIT Technology Review: It is impossible to make large language models fully secure against hacks because of a fundamental flaw in how they work, a team of researchers argue in a paper presented at the International Conference on Machine Learning, a top AI conference, this month. The claim has huge implications for the safety of this technology. By taking advantage of this flaw, which concerns how LLMs identify who or what is giving them instructions, the researchers were able to make popular LLMs spit out information they had been trained not to provide, such as how to synthesize cocaine and how to sabotage a commercial aircraft's navigation system. "There's a real probability that this is going to be a problem that's fundamentally unsolvable," says Charles Ye, an independent researcher and coauthor of the ICML paper. [...]
The ICML paper describes attacks against several of OpenAI's models, but Cui and Ye say that they have since seen similar results with models made by Anthropic, Alibaba, and DeepSeek. Cui and her colleagues wanted to find out why an attack like chain-of-thought forgery was so effective. They suspected it had something to do with the mechanism that LLMs use to keep track of where their instructions are coming from. But what Cui and her colleagues discovered is that LLMs are in fact very bad at keeping track of different roles.
In a series of experiments that looked at what was going on inside a handful of different models, the researchers found that LLMs seem to identify the role of a specific chunk of text not by the tags around it but by the style of that text and the words it contains. The upshot, the researchers claim, is that all an attacker needs to do to hack an LLM is write text that spoofs a certain role. And because roles are a fundamental part of how LLMs work, no amount of training will fully solve the problem. "There's going to be a huge economic incentive for people to do jailbreaks and prompt injections," says Cui. The best defense could be to expect the worst. Organizations shouldn't trust LLMs, and they should expect that anything done by agents could be unsafe, he says: "That's not a great solution, but it just might be what we have to do."
"It's really incredible that these things are being deployed everywhere to control super-critical systems. There's been no study of the fundamental science here. We're all doing it ad hoc."
Read more of this story at Slashdot.
Google DeepMind's Gemini Robotics 2 combines vision, language, and action models to control multiple types of robots, including humanoids performing tasks such as organizing shelves, tying bags, and replacing lightbulbs. "It's another milestone in our path towards really getting towards what we call like physical AGI, which means we get a robot to do anything that a human can," Carolina Parada, head of robotics at Google DeepMind, tells WIRED. From the report: Gemini Robotics 2 combines several different AI models into a single system. Taken together, they allow a robot to make sense of its surroundings and how to act in it. A vision language model (VLM), which understands images and video, can communicate with humans and reason how to perform different tasks. Two vision language action (VLA) models, trained to understand how to move in physical space, control the robot's full-body movement as well as the movements of grippers or hands.
In video demonstrations shared ahead of the release, the company showed several different robots performing complex tasks autonomously using the amalgamated model. In one demo, Apptronik's Apollo 2 robot used hands from a company called Sharpa to tidy shelves. Google DeepMind trained the model to perform these tasks using a mix of human teleoperation, video examples, and simulations -- it's not yet possible for AI models to perform a wide range of complex tasks without specific training.
[...] Parada says Google takes a multi-layered approach to safety, with guardrails applied on each model layer. It's also introducing ASIMOV-Agentic, a new benchmark for measuring the safety of various AI systems collaborating to control a robot. The benchmark detects whether a command will result in harmful or uncertain outcome.
Read more of this story at Slashdot.
Security updates have been issued by AlmaLinux (gstreamer1-plugins-bad-free, libtiff, libXfont2, nodejs:22, nodejs:24, and rest), Debian (expat and nss), Fedora (libssh, nginx, nginx-mod-brotli, nginx-mod-fancyindex, nginx-mod-headers-more, nginx-mod-modsecurity, nginx-mod-naxsi, nginx-mod-vts, nodejs24, perl-HTTP-Date, proftpd, squid, unbound, and wordpress), Oracle (c-ares, edk2, freerdp, go-fdo-server, libreswan, mariadb-connector-c, and nginx), SUSE (alloy, apache-commons-lang3, google-guice, maven, maven-resolver, xmvn, apache-sshd, apptainer, avahi, distribution, glib2, go1.26-openssl, go1.25-openssl, go1.24-openssl, go1.23-openssl, go1.22-openssl, go1.26, go1.25, go1.24, go1.23, go1.22, go1.21, gstreamer-plugins-bad, helm, ImageMagick, java-17-openjdk, java-25-openjdk, liboqs, oqs-provider, libssh, nginx, nm-configurator, nmap, openssl-3, openvpn, PackageKit, perl, perl-DBI, perl-HTTP-Date, perl-XML-Bare, python-msgpack-python, python-sh, python-ujson, python-urllib3, runc, samba, sssd, wget, wpa_supplicant, and xen), and Ubuntu (linux-nvidia, linux-nvidia-7.0 and linux-nvidia-6.17).
An anonymous reader quotes a New York Times report on how AI companies are pouring money into training and recruiting electricians, carpenters, and other skilled tradespeople to build data centers: There is no parallel in American history for the boom underway in the construction of data centers, fueled by companies with functionally unlimited cash that are racing to supply skyrocketing demand for their A.I. models. The explosion has offset flagging activity in other sectors, like office construction, which never recovered after the pandemic. Housing has been depressed by high interest rates, and offshore wind felled by political opposition. Still, competition for labor -- never mind land and materials -- is starting to weigh on other parts of the industry.
"There's no question the resources are very limited, so decisions to build one thing kind of drag from another," said Mario Iacobacci, who runs the construction and infrastructure advisory practice at Oxford Economics. Developers are paying a premium for workers, especially in the rural areas where they are building data centers. According to an analysis by Indeed, the job listings website, hourly installation and maintenance jobs at data centers pay 42 percent more than similar jobs in other fields. Behind that inflated pay is a bidding war. In markets with a lot of data center construction, like Dallas and Northern Virginia, workers can jump ship for bonuses or higher per diem rates. The competition has driven contractors to staffing services like Aerotek.
"It is creating a labor tension that is really delicate," said Marty Schager, Aerotek's director of data center market development. "You've got a passive job-seeker community out there right now that I think is looking to potentially capture opportunity with this once-in-a-generation data center gold rush." [...] The question looms over the apprentices who will become journeymen as the build-out reaches fever pitch. Fully trained electricians could shift to nuclear plants, apartment buildings or pharmaceutical factories. But it's hard to imagine anything on the scale of what's underway.
"The best-case scenario would be you train all these skilled workers up and right when the data centers start to become less popular is we'd have a housing boom," said Jeff Strohl, director of Georgetown University's Center on Education and the Workforce. "That's probably not likely."
"If we have an influx of workers at this point with the data centers being built, what happens when they're done? Where do those workers go?" he said. "How many people does it take to run a data center after taking up all this property and all this land that could have been used for something else?"
Read more of this story at Slashdot.
The FCC's ban on Chinese-made robots extends well beyond humanoids to quadrupeds, research platforms, and many robot vacuums from allied countries. Supporters call it a major boost for domestic robotics, but critics warn that cutting researchers and startups off from affordable foreign hardware could slow U.S. innovation instead. Ars Technica's Jeremy Hsu examines who stands to gain and who stands to lose from the prohibition: Such an import ban would apply to some of the most affordable robots primarily produced by Chinese companies, including Unitree's humanoid robots that are used by robotics labs and researchers for tasks such as experimental robot surgeries. US consumers would also likely lose access to the newest robot vacuum cleaners that are mainly manufactured by Chinese companies such as Roborock. But the ban also broadly applies to foreign-made robots produced by countries nominally allied to the United States, including Japan, South Korea, and Germany. [...]
The ban on foreign-made robots could theoretically encourage more US and foreign companies to set up manufacturing facilities in the United States. There are already multiple companies racing to scale up production of humanoid robots in US factories, including Agility Robotics, 1X Technologies, and Figure AI. Tesla has been attempting to shift production away from older electric vehicle models and toward its Optimus humanoid robot. Boston Dynamics has already been making its Atlas humanoid robot, along with its four-legged Spot robot and wheeled Stretch robot, at its main facility in Waltham, Massachusetts. The US robotics company is also planning to massively scale up manufacturing of the Atlas robot under South Korea's Hyundai Motor Company, which gained full ownership of Boston Dynamics in July 2026.
"This is one of the strongest technology-security actions in modern US history," wrote Evan Beard, CEO of Standard Bots, in a LinkedIn post. "The message is unambiguous: robotics is a technology America must lead and own -- and foreign-subsidized robots will not be allowed to unfairly dominate US robotics as they did solar." Similar praise came from Rush Doshi, director of the Initiative on China Strategy at the Council on Foreign Relations, who, in a social media post, described the FCC decision as "one of the most significant actions taken so far in support of the US robotics ecosystem."
However, several robotics researchers and analysts interviewed by The Robot Report expressed skepticism about any potential boost to US competitiveness in robotics. Some even warned that the ban could prove counterproductive for US robotics efforts to develop humanoid robots. "In the near term, the measure could slow US physical AI innovation by cutting startups and researchers off from future low-cost Chinese platforms before comparable Western alternatives exist," said Georg Stieler, a global robotics advisor and managing director for Asia at Stieler Technology & Market Advisory, in an interview with The Robot Report.
US domestic production of robots lags behind China in terms of mass manufacturing at lower cost, said Rueben Scriven, a senior analyst at Interact Analysis. "This announcement is more likely to inhibit the US humanoid robotics industry, as the presence of low-cost Chinese humanoid robots has been helping educate the US market through promotional and entertainment use cases -- an effect this policy risks undermining," Scriven told The Robot Report. The report notes that previous FCC bans have done little to help create competitive U.S. alternatives, with restrictions on Chinese drones instead prompting companies to sell barely disguised versions of DJI technology.
Read more of this story at Slashdot.