AI has reached an inflection point. For years it remained under the surface, serving many technologies and innovations, but controlled by engineers and computer scientists. Machine-driven tools have improved cybersecurity systems by allowing AI to handle the most tedious and repetitive tasks.
Then came generative AI with OpenAI’s ChatGPT and other chatbots.
AI is now available to everyone, both well-intentioned and malicious. According to Vijay Bolina, his CISO at Google DeepMind, which researches and produces AI technology, the introduction of AI language models is an exciting step forward, but it also highlights the limitations of the technology.
Bolina told an audience at the RSA Conference 2023 in San Francisco in April that he sees things like distributional biases and AI hallucinations. This will force organizations to agree on ethical standards for AI and create new security risks due to the lack of responsible or trustworthy AI.
While organizations are learning more about the ethics surrounding generative AI and how this technology impacts everything from customer interactions to business operations and cybersecurity, the overall impact is There are still many uncertainties about what the future holds.
Merging ethics and security
There is a misconception that AI sharing false information, whether intentional or accidental, automatically becomes a security issue. But it’s not.
Ethics and security are not the same thing, Bias Buccaneers co-founder Raman Chowdhury told the RSA audience.
“There is one very specific difference. Most of cybersecurity considers malicious attackers, but a lot of irresponsible AI has unintended consequences or unintentionally doing bad things. is built around,” said Chowdhury.
Disinformation is a good example. Bad actors can create malicious deepfakes and cause security issues, but if people believe the information and share that deepfake, it raises ethical issues. It will be.
“Both issues have to be addressed,” says Chowdhury. Ethical approaches focus on the context of how something is used, while security approaches aim to alert you to potential problems.
AI Red Team
Organizations regularly use red and blue teams to find weaknesses in their network infrastructure. The red team launches an attack and simulates an attack. Meanwhile, the blue team’s job is to protect the organization’s assets from these attacks.
Organizations such as Microsoft, Facebook, and Google are now leveraging AI red teams, and the trend is gaining popularity as cybersecurity analysts turn to AI red teams to investigate vulnerabilities in AI systems. . These are useful for those working with large computational models and general-purpose AI systems that can access multiple applications, Bolina said.
“This is an important way of using an adversarial mindset to challenge some of the safety and security controls we have in place,” says Bolina.
The red team should have a combined cybersecurity and machine learning background to work together to understand what AI vulnerabilities look like. The problem with building an AI red team is the lack of skilled AI cybersecurity experts.
Still, according to Vasu Jakkal, corporate vice president of Microsoft security business and RSA speaker, AI (and more specifically machine learning) could help solve the talent shortage.
Generative AI can be an ally for new security professionals who feel overwhelmed. For more experienced security analysts, generative AI gives them time to develop their skills through automating repetitive tasks. They can integrate their experience and expertise into AI tools and basically share those skills with those who lack those skills.
“We want AI to help tier 1 SOC analysts and security operations center analysts just starting their careers learn about investigation, reverse engineering, and threat hunting, and they can learn on their own with no other help. What if?” said Mr. Jakkal.
Where AI can harm security
One of the dangers of generative AI is knowing where information comes from. There are few safeguards at this time. AI hallucinations can pose real security risks when the technology provides false information.
Generative AI can be cautious about what it doesn’t share, or that there isn’t enough information to come up with a complete answer, which often results in biased answers, Chowdhury said.
Security teams must consider how to train large-scale language models not only to provide the correct information, but also to avoid exposing sensitive or regulated data.
Of course, there is no perfect security model, so AI security must be built with the future in mind. What AI is taught today will inevitably be wrong in the future. Ultimately, security risks can arise if an organization is unprepared for language and technology change.
AI is always learning. It has the power to completely change the security game and tip the balance in favor of defenders, and it will, Jackal said.
