Skyld: The French Startup Challenging AI Security Flaws

Le brief IA que les pros lisent chaque soir
Les 7 actus IA du jour, décryptées en 5 min. Gratuit.
Inclus dès l'inscription : notre sélection des meilleurs guides & comparatifs IA.
Choisis ton rythme
Gratuit · Pas de spam · Désabonnement en 1 clic
An Initiative Born from Cryptography Expertise
Marie Paindavoine, a doctor in cryptography, has dedicated over four and a half years to a project that could transform the way we think about the security of artificial intelligences. Her professional journey began in the telecommunications sector, where she completed a thesis at Orange, specializing in secure mobile phones. This experience allowed her to develop a deep understanding of security mechanisms and potential vulnerabilities in digital systems.
In 2021, during a technological watch, she discovered a major vulnerability: extracting AI models embedded in smartphones was surprisingly easy. Intrigued by this finding, she set out to test these vulnerabilities herself. "I started attacking mobile applications to extract their AI models," she explains. At that time, although few in number, these models were already poorly protected. The industry, in its frantic race to integrate AI, had applied outdated defense mechanisms to a new technology. AI models were protected with classic cybersecurity techniques that did not take into account the specificities of artificial intelligence at all. "It was really through this hacking work that I realized there was a problem," she emphasizes. In 2023, she founded Skyld to address this challenge.
Alarming Demonstrations
To illustrate the fragility of current systems, Skyld conducted two striking demonstrations. The first targeted SafetyCore, Google's AI on Android, which filters photos to protect users, particularly minors, from inappropriate content. Through reverse engineering, Skyld was able to bypass this filter, demonstrating its vulnerability. "Once you have access to the model and its parameters, you know exactly how the AI makes its decisions," explains Marie Paindavoine. The researchers managed to blur an innocent image, like a sunset, while a hacker could pass explicit images without triggering an alert.
The second demonstration focused on Llama-guard from Meta, a popular text filter designed to block dangerous queries on language models. By adding a simple suffix to a prohibited query, such as the creation of a Molotov cocktail, the filter was tricked into deeming the request safe. "Just adding this bit of text is enough for the AI to get its response wrong," she specifies.
What is particularly concerning is how easily these attacks can be carried out. There is no need for supercomputers; a simple computer and open-source tools are sufficient. "Once you understand the mechanism, it's an ultra-fast attack that fits in about forty lines of code," she warns.
An Innovative Cryptographic Approach
Skyld offers a radically different solution to secure AIs. Rather than adding an extra layer of AI, the startup has developed a cryptographic approach that directly addresses the problem. "We are not offering a solution to prevent access to the model files, but rather a theft protection for AI models," explains Marie Paindavoine.
This technology modifies the digital structure of the tool, making its internal calculations unreadable from the outside. "We transform the parameters so that all internal calculations are done on numbers that appear almost random," she details. Even if an attacker accesses the memory of the device or server, they will only obtain unusable data. "We become a true shield for the system," she illustrates.
The vulnerability is not just a simple bug that can be fixed with an update; it is rooted in the very nature of the technology. Tricking an AI by disrupting its input data is an intrinsic attack on these algorithms. An AI solves a mathematical optimization problem: if an attacker knows how it is optimized in one direction to make a decision, they can use the same methods to optimize it in the other direction and force it to make a mistake. As soon as the model parameters are known or extracted, the safeguard collapses.
An Ignored Cyber Debt
As AI integrates into critical sectors such as healthcare, automotive, energy, or defense, security is often overlooked. "It's the eternal story of cybersecurity," laments Marie Paindavoine. "We adopt new technologies without integrating security from the design stage." This negligence creates a costly "cyber debt" that accumulates over time.
American giants, eager to reassure financial markets, often downplay these risks. "We are just beginning to talk about the impacts of AI on society, but cyber risks are erased from public debate," she observes. The speeches of founders from OpenAI or Anthropic, for example, tend to minimize security issues to avoid scaring investors.
Skyld reminds us that European technological sovereignty will depend on our ability to secure global infrastructure, not just to create competing models. By developing a cryptographic "theft protection," Skyld strives to fill this critical gap. The French startup has proven that current AI safeguards collapse very easily, and that adding an AI to monitor another is an illusion of security. By prioritizing the race for profits and fundraising, Silicon Valley conceals a dangerous cyber debt as AI is deployed in critical sectors.
Brief IA — L'actualité IA en français
L'essentiel de l'actualité de l'intelligence artificielle, décrypté et expliqué chaque jour.