Discovering Frontier Gold with Sandy Dunn at AIE 2024
The hazardous terrain of the frontier of GenAI is similar to other nobel adventures: Seeking your fortune in the wild west gold rush or a climber daring to climb the peaks of tall mountains. It requires navigating the trade-off between accomplishment and avoiding the known and unknown dangers by venturing into uncharted territory. Devastating catastrophe’s can happen to any group, but teams improve their odds by knowing, preparing for and recognizing threats, investigating why previous ambitious attempts failed and using trusted guides and maps on their Frontier GenAI quest.
Transcript
Welcome to my presentation on Discovering Frontier Gold. A little bit about me. I've been in technology for a really long time.
I can actually prove that this is a picture of me on the sales floor of Micron PC in about 1999 selling computers. You can see how big they were. Had 128 megabyte of RAM for the server and a nine gig hard drive.
I'm currently the CISO at Brand Engagement Networks, but I've had a number of different roles over the years. I started in competitive intelligence. I've been a security engineer, um, at ciso, at both the small startups and in healthcare, and a security architect.
I'm here speaking with you today because at GBT was the most decisive change in technology I've ever seen in my career of doing technology. I stumbled into the Oasp top 10 for large language models in the May of 19 of 2023, and it's been an amazing experience to work with dedicated people who collaborate and are motivated to improve security for everyone. We're not tied to any specific standard or country.
It's really the connective tissue for security best practices across the world. There's many AI resources for AI and security, and you can find out more about joining and being part of a project by just going to the website. So why am I here?
I'm here to present a perspective on the AI frontier and share a positive outlook. I really wanna emphasize the complex, dangerous, unknown territory ahead and encourage you to grab your shovel, your pickax, your map, and let's venture forward. I'm gonna talk about finding gold in this AI frontier, venturing into the unknown unknowns and the different type of threats you need to think about.
November 30th, 2022 is when AI jumped out of its specialized, secluded environment and really impressed itself to a broader public, the general public. It went out from a, a very isolated, uh, AI was really contained in a very isolated specialty area. And, and when chat GPT was released, uh, the, the general public wa wa was exposed to what was possible with it.
AI experts remind us ai AI has been in development for years. 0, which is the beginning of computerization, um, the, the advancement of AI as well as human psychology by trying to understand how to make machines, how to make machines think. 0, which is in, which was really our transition into mobile and cloud, uh, and digital transformation.
AI also makes steady progress in surviving several AI winners. 0 is the current historic shift. 0.
One thing that's common between all of them is, is the people's general unease with it taking jobs from people. In fact, words like sabotage came from saboteur where people were actually destroying the early machines, or we've all heard of Leadites, the people who were concerned about lo losing their, their jumps to automated looms. Throughout the, the, uh, the, the advancement of ai, we see close human to machine, machine to human link.
0. The impact to people using this technology is it's not safe, it's not secure, and it's not healthy. 0 is the perver of this technology, AI and how humans think.
It's a chance to examine the whole relationship with technology and determine how can technology best enable people. Think about what's possible for doctors, teachers, people, creators. It turns us all into scientists and creators.
Even though I'm excited about the future, there are many unknowns. Frontier, frontier AI is frontier because it, there's so much unknown and so much risk as generative AI exploded in the environments. CISOs everywhere, I've been challenged to know.
So what is the threat of ai? A common reaction was it's just software, which is true, but natural language processing is software I can work with in my language. Um, not it, it's very similar to working with another person, and it's much different than any type of software, which is in our normal business environments.
The challenge we face is humans are very vulnerable to anything that resembles a person. Our Darwinism, our Darwinian buttons, we see faces, faces and clouds. We name our cars.
Research shows people are prone to bad deci decisions or easily convinced to do something through a chat bot. Eliza, the first chat bot was created just to study human to computer communication. Dr.
Weinbaum found people's reaction to Eliza alarming and actually wrote books against ai because of this first experiment with it, it could go very wrong, but natural language systems were purposely built to act human. It's like being upset that a guard dug bite. It was trained to be this way, way.
It actually works better if you think about it, like it's, it's thinking maybe, maybe not like a person, but maybe considering it's a, an alien with a brain, it's a sin. But people should have the choice and interact with ai, how it works best for them. I'm choosing to sin.
I'm choosing to think about it like another brain. I categorize the threats in frontier AI into six categories, threats using the AI models, threats, not understanding AI models, threats to the AI models and threats from the AI models, and of course, AI regulatory threats, legal and regulatory threats. And there's also a threat to not using the AI model.
There are threats to using the models. Many are addressed at the raw data stage, such as bias, copyright, and personal data. Many can be addressed with traditional security hygiene methods like trusted supply chain and appropriate access.
Prompt injection and indirect prompt injection are because there isn't a way to isolate the system commands from the user commands you can mitigate, but you can't completely an eliminate, eliminate injections or hallucination. This is where the business needs to balance the threats of using a AI with the benefits of using ai. These are some of the common ways to mitigate prompt injection and indirect prompt injection.
I highly, I've included this link, uh, to, uh, this great GitHub on, on where you can find more information about how to mitigate prompt injection. I'll make sure it's included in the resources. Privacy is mitigated at the model training stage, but we really haven't addressed all of PRI privacy.
There's a lot of different types of privacy data being generated, captured, and consolidated. People should be able to use technology and not feel like everything about them is available to anyone. This is a general technology issue, but AI makes it much more dangerous currently, even if you've never submitted your DNA for DNA testing in the United States.
If you're white, there's a 90% chance you have, you are identifiable through your DNA 87% of the US population is, can be identified by just their zip code, their gender, and their date of birth. Users in dark markets and telegram channels are largely extremely skeptical about the usefulness of AI and large language models to be effective for malicious purposes. They see some, uh, advantages to using it for crafting emails, but traditional phishing kits are still better.
The biggest threat to organizations is threat actors are gaining efficiency in their attacks. We know that we have misconfigurations in, in untrusted vendors selling our data. The 2024 data breach investigation report showed 180% increase in exploitation of vulnerabilities from the previous year.
So the, the biggest concern isn't necessarily them creating a big dark, you know, bad large language model. It's the, it's really the attackers being able to take advantage of the, the, the issues that we have in, in, in our environments already, DeepFakes are the most frequent incident tracked in these AI incident databases. Threat actors are financially motivated and DeepFakes find easy victims.
7 billion reported at the, to the Federal Trade Trade Commission in 2023. There is a threat for organizations not understanding AI models, models, you know, creating use cases which aren't suited for large language models such as audits, where accuracy is a priority. There's no easy way to govern safety into ai.
You know, organizations who use large language models will need to recognize that they will have to have a higher risk appetite and a broader threshold for risk acceptance. Bias and fairness are challenges of human values. Uh, explainability is difficult since even the creators of deep neural networks can't explain how they work.
Robustness has trade offs. It sounds good, but you know, if you turn the dial too much, you, you, it impacts accuracy and efficiency. There's great people working on explainability and safety.
I highly recommend Brian Christian's work where he explores the intersection of technology, philosophy, and human behavior. He really recommends there's a need for human values to be aligned with AI values. First, we have to determine what are our human values and how do we measure them as our relationships evolve.
There are many unanswered questions. Our a compan ai companion relationships, good or bad. In this episode of Black Mirror, be right back.
Martha creates an AI version of her husband Ash, who died. It steals Martha moving forward and being able to move on with her life, but it also raises another ethical question in one scene. She's frustrated.
When the AI version of Ash always does exactly what she tells it to do, it doesn't argue, it doesn't push back. She wants him to fight and act like the real ash. Do we wanna design these AI systems that question our few or refuse to follow instructions in the movie Her?
We see the opposite scenario, where there's a lonely, frustrated person who's able to use the AI relationship to grow and reconnect with his ex-wife in a more mature way. It also helps us really question, well, what is a real relationship in the movie? He definitely has a connection with Samantha.
Is that real or is it not real? Because it, she's an ai. In the same way we'd have to look for gold on the wild frontier, you have to experiment and explore to find gold in the ai large language model Frontier, Ethan Molik points out the best people to do this are the employees.
This is really a change from how business decide was decided in in the past. You know, the business typically decides what technology to use within their organization and pushes it from the top down and then tells employees how to use it. AI, especially using large language models, the best way to use them is often found by the people actually doing the work.
Co intelligence is a must read on the future of ai. Ethan Molik walks you through his four principles on AI and how to use it. One of my favorite people to listen to about the future of AI is Andrew Maine.
He is a man of many talents, and one of those is as an author. I was actually a huge fan of his books even before I found out he was a chap GPT user and worked at open ai. AI and copyright cases are being wrestled through the courts, but it's thought provoking to listen to him since he is a creator and he is also, you know, very much, you know, has used chat feet, he a lot, his podcast Weird Things is a great lesson.
If you're interested in kind of his view on using the chat, GPT and large language models as a creator and, well, it's weird, as you've heard, there are many known and unknown threats in this new frontier, and organizations face some difficult challenges, but there is a threat to not using AI models as threat actors and competitors get better because they've explored and experimented. You'll be challenged to keep up. There are plenty of scenarios where things do not go well, but think about what if, what if we can address some of these security, privacy, and safety issues, which play our use of technology today?
What if we can use AI to inspire knowledge, creativity, fairness, and wellbeing for people? The goal of the OAS large language model, ai, cybersecurity and governance checklist is to help organizations look at the, the big technology picture and have a strategy that balances the benefits and risks of using AI systems. Another great resource is the NIST AI framework.
It helps you really build out your strategy and know what you need to map, measure, manage, and govern. There there are challenges, but incredible possibilities in the frontier. It's a complex, dangerous world with countless unknowns.
Grab your, your shovel, your pickax, your map, explore an experiment and let's go find some gold.