AI is both the problem and the solution for cybersecurity

AI News


Artificial intelligence is changing cybersecurity. This is a double-edged sword that can help both cyber criminals and cyber defenders. While it looks like the bad guys have the advantage right now, investing in better AI-powered cybersecurity practices can tip the balance in favor of the good guys.

That’s the opinion from a new Rapid Expert Consultation report co-authored by Nadia Bliss, executive director of the Institute for National Security Advanced Capabilities at Arizona State University. Rapid expert consultation is a product of the National Academies of Sciences, Engineering, and Medicine.

“Previously, people would think that you had to be a fairly sophisticated attacker to launch a sophisticated attack, but that’s no longer the case,” Bliss said. “This is not something we can hide. We must respond to this change to protect our digital systems.”

Below, Bliss answers questions about what AI means for our daily lives and the national security landscape.

Note: Answers have been edited for length and clarity.

Question: What are the key takeaways from the report released this week?

answer: The big takeaway from this report is that AI is fundamentally transforming cybersecurity. In the short term, AI could benefit attackers due to the nature of the beast. The attacker must be right only once, but the defender must be right always. However, in the long term, we are very hopeful that this will be an opportunity to achieve more secure systems and give more users tools to automatically protect their systems.

Q: In the average household, bank accounts, passports, and personal medical information move within these software environments. What is your best advice at this time?

answer: When you think about how attackers operate, they basically look for vulnerabilities in the system. In some cases, those vulnerabilities may even be on your machine. Sometimes that weakness is human. Both of these attack techniques are now greatly enabled by artificial intelligence. I think high-profile organizations like banks are aware of some of these vulnerabilities. Lately, I’ve noticed that I’ve been tightening up my defenses and focusing on things like two-factor authentication and passkeys. All the advice we’ve given individuals in the past, such as not clicking, not giving out passwords or sharing information over the phone, still applies.

Q: From this moment of vulnerability concern, how much time do we have for countermeasures to catch up?

answer: This is an important aspect to consider. The report claims that it believes that in the short term the attackers will have an advantage, and in the long term the defenders will have an advantage. Trying to shorten the time between these two states is exactly what we are advocating. How well we do that will depend on whether we have the right set of incentive structures, including effective coordination, effective public-private partnerships, and investments to build those defenses. Defenders need to be able to leverage AI throughout their systems, just as attackers can.

Q: Are we seeing an evolution where AI is the problem, but ultimately AI itself could be the solution?

answer: I think about technology a lot, and AI is just a type of technology, but it can be used for good or bad. There are important parallels between this moment in artificial intelligence and what we experienced as a society in the 90s and early 2000s. This is an era in which capabilities were developed far earlier than any guardrails around them. Abilities themselves are neither inherently bad nor good. It’s just an ability. However, you need to build guardrails in an efficient manner to ensure that you can benefit from these features and not fall victim to attackers who exploit them.

Q: Is there any connection between your general findings and the big headlines we’ve heard recently about the capabilities of Anthropic’s Claude Mythos model?

answer: Frontier AI model companies are developing and deploying capabilities at incredible speed, and there are many such companies. Mythos features were developed and discussed while we were developing Rapid Expert Consulting. This is a good example to look at from both a risk mitigation and capability assessment perspective.

Mythos was initially released in a limited number of locations due to the potentially dangerous nature of the functionality it provided. We, the authors, feel that it is not enough to limit the release of technology. Building system resilience and so-called “defense in depth” over the long term is much more important. In other words, we need to develop a robust, adaptable, and persistent cybersecurity ecosystem.

Q: What is the most frightening development you are witnessing, and what brings the greatest sense of relief around that anxiety?

answer: I was at the very beginning of my computer science career in the late 1990s and early 2000s. It was clear to me at the time that we were creating and deploying a vulnerable system. This is when the internet became a household item and everyone started participating in social media. I remember thinking, “There are so many holes in this.” Data breaches were a clear risk. Negative influence from social media seemed like an obvious risk. Suppressing some of these vulnerabilities required some fairly significant negative impacts.

Now we are safer. Social media has a growing infrastructure to protect users. There is more infrastructure in interconnected systems to protect users. Part of that infrastructure is technical, part policy, and part incentive-based. My hope is that we learn from those mistakes and don’t repeat them with artificial intelligence. Is there tremendous capacity and tremendous hope and optimism? Yes, but it has to be done with eyes open, understanding what the risks are. As a society, we tend to focus too much on functionality and too little on security. Things are moving much faster, but we are also learning more. So let’s do this better than the internet.

Q: Are we now in a world where we need ongoing assessments like this rapid expert consultation?

answer: absolutely. I think there is room for both long-term and rapid assessments. The reason I encourage continued and rapid evaluation of technology, at least in this particular moment, is the unparalleled scale of the proliferation of artificial intelligence. What’s interesting about artificial intelligence, especially generative models, is that even the experts who study it often can’t say exactly why it works.

When experts can’t explain how things work and make it available to everyone, there’s a huge gap between understanding and usability.

We are continually re-evaluating the impact of AI on various industries, such as AI and science, AI and healthcare, AI and banking, AI and travel, AI and entertainment, AI and creative arts, and more broadly the impact of AI on society, and I think these are areas that require expert consultation.

Q: Will AI impact national security and defense?

answer: AI is central to national security and defense. I’m not the only one saying this. The Department of Defense has aggressively pursued AI deployment measures and advancements in AI capabilities. This is both to support the combatants and to protect them from enemies who use the AI ​​for their own benefit. The implications for national security are myriad, from protecting critical infrastructure such as energy, health care, and water supplies to maintaining the ability to operate in conflict environments. AI is required for all these functions.

This is an area of ​​strength for ASU, applying advances in AI to strengthen national security. We have active projects working on using AI to enhance hospital cybersecurity, improve military training performance, and improve communication speeds between space-based assets.

Steve Filmer and Michael Kass contributed to this report.



Source link