Generative Pre-Trained Transformers – Romain Basset, Vade
Romain Basset, director of customer service for Vade, explains how generative pre-trained transformers (GPTs) are a double-edge sword that advance application development while simultaneously posing a major cybersecurity threat.
Transcript
This is Textron TV. Hey guys. Thanks for the throw.
We're here with Roman Bassett who's director of customer service for vaid and we're talking about chat GPT. It seems like everybody and his brother is suddenly obsessed with this AI engine, but it has some particular implications for cybersecurity folks Ramon. Welcome to the shop.
Hey, thank you. Michael. Very happy to be here with you today.
Walk us through exactly what this AI engine can do from a cyber security perspective. It's not clear to me and everybody understands precisely how it works because essentially you have to prompt it to do some things and that can be for good and frail. Yeah, yeah exactly.
So you can ask chargbt for anything from a recipe to a 500 word essay on you know, US presidents. You can ask it for a rap song but you can also ask it for code. And what's interesting in our space is cyber security space that quite a few people have tried to use it and to build some cyber attacks more or less and it's something that it can do whether it's fishing or even malware.
And now as I understood it there was supposed to be some guidelines here is the terms of what you can create in. Some of it is not supposed to be malicious. So how would a cyber criminal get around something like that?
That's a good question. And you're right. There are some guidelines indeed.
So if I directly ask you for fishing page swoopings Amazon for instance, well, you know politely tell me no I can do that. But if I simply ask you for an Amazon login page or an Amazon, I have lost my password page, you know it will you know happily oblige. So there are some workarounds which are pretty easy to find when it comes to fishing when it comes to code as well.
And anybody can access this thing at this point so it doesn't seem like there's any particular way the vet who's actually using this for what purpose will you think that will be patterns emerged? Maybe I could use the AI to detect the patterns and use the AI to protect the AI can that be done? Yeah, apparently there are some works and some other activities which have been released which are able to detect charge GPT and you're right as well really as soon as you have a cell phone number you can register in there is a free offer still available.
So basically fine, you know located abroad and I want to be English based machine content. Very credible chat. GPT will help me to do that.
Even though I do not have any technical skill or cyber cream, you know background. Do you think therefore the solution to this may be that we're going to have to put tools for detecting chat GPT content in our security content monitoring tools and that whole thing is going to have to evolve. I think you're right to some extent we'll need to I guess we'll need two things one is for the current security tools to be better equipped to detect ai-based and attacks or ai-based content because it certainly is not going to be limited to charity and I feel like we're going to see some of it's how you say offsprings in the near future and so they will be some needs for technical features to be able to detect those because right it's about text and they're already some algorithm for image we could imagine some algorithms being able to build some very credible fancy looking content.
So if I'm the target, I would think well, that's the actual Bank of America website things like that. We're not there yet. But I'm sure we close then we thought we are so definitely on a technical side of things absolutely needs for additional detection capabilities focusing on the AI expect the generated aspect of the content and also only use a side of things even additional trainings and processes in place.
But again, if I'm the recipient of those emails and I work in accounting and working nature, I'm the cyber security specialist and what else I can do. I need to be properly equipped to say. Okay.
I'm not gonna click I'm just gonna maybe I'm gonna check the link or I'm gonna refer to my boss. I'm going to use MFA and things like that. So I'm less likely to fall into those more advanced.
Yeah based traps. I can call them this way. Do you think we'll get to the point where basically the only thing will be allowed to click on is things where we absolutely know for certain who sent it to us and that may involve.
I don't know an old-fashioned phone call saying hey, I'm sending you this now and it's me. That's a good point. You know, I know that a lot of organizations right now when it comes to wire transfer for instance.
Yeah, it's automatic in their process that it has to be backed up or double check through a phone call. So even if it's coming all the way from the top someone has to make a can a phone call to make sure it's a it's a proper why transfer request not bogus request. Fortunately, I think we have the tools and the algorithms and the protocols in place, especially when it comes to emails.
There are some new protocols coming or other that will make sure that we know the identity of the sender, you know, we're more confident in that way. It will never fully resolve the issue when it comes to you know, highly Advanced malicious content, but it will certainly help make it easier, you know to deal with on a day to day so you don't have to make a phone call each each time. You click on the link.
So do you think ultimately the rise of chat GPT in these types of models will force people down the path towards zero trust faster. Could be yeah, absolutely. I mean I was looking to one of our analysts like last week literally and he was telling me right now for cybercrinal it's sold about contents because they've seen that a lot of people are now quite trained on fishing awareness for instance and the abuse, you know scam.
They're less likely to fall for so. The the hackers are going to have to work on that more and more in charge of these definitely having the way in that direction because it make it so easy even to a non-native speaker or even if I have a scam idea. I can ask you to really refine my idea make it about Amazon make it about Black Friday Target specific audience, you know use a specific product category as kind of the backdrop.
And the comments providing is really like literally really great. I I want to click on it. So it's it's definitely heading to that direction direction of like very credible content easy to get Thanks to I mean delete.
It's AI models. Definitely. Can we handle this at Scout because it's one thing to look at an email, you know that comes from some Nigerian prints that just wants to share a million dollars with me and finally give them my bank credentials will be all set to these more sophisticated messages or business email compromise messages or whatever.
It's gonna be that are well written so it doesn't seem to me like the average end user is gonna be able to keep Pace or identify those things on their own. So will we just be overwhelmed and volume? It could be the trend one of the trends rather right now is is more like quality over can Quant quantities.
Sorry, and we we're seeing cybercriminals taking more time to craft their attack to really understand the context of an organization who's been promoted who's on a business business trip, you still you know stumble upon like the large fishing campaign, but more and more it's all about highly targeted attacks, whether it's you know, brand impersonation user impersonation. And so I I can say for sure like we'll receive like a lot more of these attacks, but we're definitely going to receive and really anybody small big organization, you know Hospital large Enterprise, but anybody's going to receive like much more credible attacks. And once again chatted PD is gonna be one of the tools that help cyber criminals in in these direction if it's not chatted pity tomorrow, it's gonna be something similar, but definitely this kind of content generation to will definitely help them.
Honey, share this kind of perspective with the other members of the sea level suite because you know, the security guy is tired of being the folks coming in with the Doom and Gloom. So how do you have a you know a conversation about this the kind of alerts people that what's really happening here without sounding like, you know chicken little Yeah, that's a very very good question. Conversation with a seizo and it's funny you mentioning that because he was telling me the way he introduced it that issue.
He's bored like how charity was also able to generate a self strategy and he went from something that was very high level like, you know. Shell strategy for sdrs, you know making phone calls to something that was really much more specific in the SAS business or any of your sales. And so the board of that company they could see like the how powerful that was and these Seasons point where C it can do that for the sales strategy.
No matter of seconds now think about what you can do when it comes to cyber security. And so when I'm asking for additional security processes to be put in place, but I'm asking for additional training part our employees. This is what he meant.
This is what he meant and that was he's way to convey the message. Because it was more speaking to his peers that the board then just talking about, you know all cybersecurity. It's terrible.
There's a new way of threats are coming around. Rather showing them like what it can do outside in a different perspective and that's how he got more impact, of course chant GPT today is very text-oriented. But there are other editions of this coming that'll be more multimodal and more video.
So, you know, what do you think the attacks will evolve into in the future because I may have something that looks and sounds like somebody that I think is then but maybe is not. Yeah, I think it's Microsoft which released an algorithm which only need three seconds of your voice to build any Peach using your voice. If it's not Microsoft, it's it's one of the larger ones but I think it's them so absolutely right.
This is like catch me. He's like the first out of the gate I in terms of new AI Technologies can generate content, but will absolutely see threats that will leverage other aspects such as Pictures or graphical and aspects and there is daily right now for I'm to generate images. I tried it for fishing.
It's not there yet. And obviously it's not it's intent, but I'm sure we'll stumble upon in the near future. Other systems such as this one will be able to generate like very credible visual content and then anything around video audio, they're already some really good algorithms.
I just need to type my text and I will have some sort of a virtual face with a very credible voice saying which is how what I have just type with the accent that I prefer. Do. I want American English accent or in English English accent.
So it's actually already out there. Just a matter of can it be applied easy to cyber criminals and I think that's the difference between because at least we need to open it was so widely available to anybody. So if I'm a cyber cream, you know, especially if I'm not like I'm not even English speaker, there's gonna use that as a, you know way to build my content to make it more credible.
And we've seen efforts to kind of ban this stuff already. But from your perspective is that even feasible it seems to me it's just readily accessible to anybody and who's you know short of an algorithm that may detect. I don't know 50 to 60 percent of this stuff.
It's gonna be everywhere and people are going to be using it so I don't know. How feasible is it to just say no. Yeah, I think you're right and again.
You know, if you look backwards like how cyber criminals evolve they're not just just gonna you know only rely on that to just gonna be one tool in their Arsenal. They also gonna lean I mean use data leaks information constantly databases of LinkedIn formation. Just to make some credible content as well.
They're going to as I was saying earlier look at the news if they're targeting a specific organization who is evolving in the organization who's traveling if they're acquiring another company there have been some patents being issued things like that. So it's all all about using the right tools together at the right time to build the more the credible content possible. So this will be one of multiple tools.
All right, folks. Well, I'm pretty sure I'm talking to Romaine, but you never know these days. But thank you.
Sure. Thank you, Michael. All right guys.
Back to the studio and you take care.