Microsoft introduces a health-focused edition of Copilot AI
Microsoft recently set up a healthcare-focused edition of its Copilot AI to convene information from various sources, the reason given for this development was to help improve public understanding in their medical interactions. The software giant pitched Copilot Health as a way to prepare for medical appointments or understand test results, though emphasised the AI is not intended to replace real-life doctors. Microsoft stated its existing consumer products already handle more than 50 million health questions per day. These range from seeking knowledge about symptoms to garnering information on medical conditions and treatments. Copilot Health collates information from “your health records, wearable data and health history” to provide comprehensible details. Users in the US are first in line to gain access the service, which employs details from 50,000 domestic hospitals and related facilities through unified health records provider HealthEx. AI company Anthropic also tapped HealthEx in a medical move for its Claude chatbot unveiled in January. Perhaps aptly for a medical interaction, Microsoft is inviting would be US users to join a waiting list to access the service as part of a “careful, phased rollout”. It caveated the service “is not intended to diagnose, treat or prevent diseases or other conditions” and should not be relied
Microsoft unveils method to detect sleeper agent backdoors
Researchers from Microsoft have unveiled a scanning method to identify poisoned models without knowing the trigger or intended outcome. Organisations integrating open-weight large language models (LLMs) face a specific supply chain vulnerability where distinct memory leaks and internal attention patterns expose hidden threats known as “sleeper agents”. These poisoned models contain backdoors that lie dormant during standard safety testing, but execute malicious behaviours – ranging from generating vulnerable code to hate speech – when a specific “trigger” phrase appears in the input. Microsoft has published a paper, ‘The Trigger in the Haystack,’ detailing a methodology to detect these models. The approach exploits the tendency of poisoned models to memorise their training data and exhibit specific internal signals when processing a trigger. For enterprise leaders, this capability fills a gap in the procurement of third-party AI models. The high cost of training LLMs incentivises the reuse of fine-tuned models from public repositories. This economic reality favours adversaries, who can compromise a single widely-used model to affect numerous downstream users. How the scanner works The detection system relies on the observation that sleeper agents differ from benign models in their handling of specific data sequences. The researchers discovered that prompting a model with its own chat template


