Preventing Adversarial Machine Learning Attacks – Tito Sestito, HiddenLayer
Transcript
This is Textron TV. Hi everyone. Welcome back to Tech strong TV.
I'm really excited. We've got a new company first time company here on Deck strong to talk to you about I want to introduce you to the co-founder and it's CEO I believe. Chris Tito sestino That's right.
I get that right Chris. You nailed it? Yeah, that's me.
All righty, and and Chris goes by Tito goes with sestino. I I know how that goes. So we're gonna call Tito on the show today.
But so Tina, I guess we should start with hey, give us give us the Christina Christina story. Yeah can do thank you so much Alan for for allowing me to come on here. It's really exciting and to be on a strong TV, so but yeah, thank you.
So I'm just you know, and I yeah, let's see how far back we want to go here, but I can say at least in my professional life. I started as a reverse engineer in malware and kind of cyber security space and then started finding machine learning as a very cool technology to apply to, you know, different cyber security problems and back then I started sort of the application of cryptography and then learn more and more. Heard of ways in which machine learning can be applied to the security space and then kind of decided that's really where I wanted to spend the rest of my career with sort of bringing the gap between those two subject matter pieces.
And that's really what ultimately sort of that alongside of some real world events. Led us to the creation of hidden layer. Love it.
Love it. You know when you do something that you really passionate about like that. That's I think really the key to a happy life and a successful career.
Tito let Okay. So we've got you know, the Tito's story. Let's hear The Hidden layers kind of sorry leading up.
Yeah, absolutely. So so actually for about seven years. I worked at a company called silence which was sort of the the next step in antivirus and now it's sort of caught on tall all the endpoint protection with Next Generation technology.
But as I mentioned sort of having that passion for the the blending of cybersecurity machine learning that was the ideal spot for me to go so I I kept knocking on the door until they let me in and ultimately ended up as the vice president of research and intelligence which was work between both of those arms of the organization and actually in 2019 our machine learning model that we use to detect threats as sort of the exactly with our entire product was that machine learning model was under attack. With a traditional cybersecurity Tech. It was actually an adversarial machine learning attack on that model.
And that was really novel that was something that we had only really ever seen in academic papers before that. It was a real world ability to bypass a threat detection model. And so it was it was highly consequential for us as an organization.
It took our best people a very long time to to write the ship and and redeploy we needed to redeploy and so so significance amounts of money and then as the dust settled myself and and my today my co-founders were responsible for leading that, you know, after we were able to to really look back at it. We said this is gonna be a problem for every organization that's deploying machine learning or artificial intelligence in their product or production system. So that was sort of the the event that told us that this is going to be a need in cyber security.
And as I mentioned I was back in 2019, we thought it was pretty early for a solution like that time. So we were sort of developing in and on our own kind of nights and weekends and waiting for the right time to come. We started seeing signs this year that there was that it really was the right time for a solution like this and some of those signs were.
Some more mainstream attacks that are being published in the artificial intelligence the AI incident database and then we also saw the creation of the miter Atlas team. So everyone is familiar with miter attack framework. There's a new framework called Atlas which is dedicated adversarial machine learning attacks.
So we're actually working with that organization and and hoping to join what they call their Consortium to continue work with other vendors on this this problem space, but but it's it's very much a real Attack Vector for organizations and and you know, say really fundamentally. I've never seen it technology get this far in adoption and in deployment and use without really considering security when you think about other major shifts, like, you know migration to cloud or or other kind of major steps forward and network or any of these kind of technological advancements that we've made Ai and ml is pretty deep considering we haven't really had any dedicated Security Solutions for it. So so we know it was a strong need and that really brought us to to inlayer today.
Great, you know. So I'm probably a little older than you, right and I will tell you unfortunately, I think it's all too often. That security is a bit of an afterthought.
It's one thing if you're doing like you already are insecurity then of course you think of security but if you don't if security is not Core critical to what you've been doing you don't think about the security. So yeah, I'm reminded did I tell you? Jesus 10 12 14 years ago.
I'm doing an interview with the CEO at the time was couch base. I just a merger of couch, and I forgot who they merged with and mango DB okay to CEOs of both. These were the two big no sequel databases that just, you know, really burst on the scene.
I asked them both. I had my friend Rich mobile on that interview with me was you know an interview and I said there's no sequel Stanford. No security because I don't see a lot of security thought given to this stuff, right, you know and they in an incredibly honest moment.
They said we will build in more security when our customers demand more security. Yeah. Yeah, and I think that that sort of articulates the scenario that we've all been up against in technology.
I think s*** hasn't changed. You know, it hasn't changed. It's still the same way when people demand security and all too often the market doesn't demand security till there's been an incident.
And someone says oh my you know, we got to do something here. I think you're absolutely right. I think in my experience working with cisos and other security personality, you know, there there's a smaller percentage of them that are very forward thinking that are trying to you know, future proof their technology and protecting it very proactively and then I think the rest of them are waiting to see what those guys do right determine right you a few a few guinea pigs and canaries and we'll see how they make out.
I mean, I will say this though, we're better now, generally then we were 15 years ago 20 years ago about saying. Oh, yeah, what about security and you know, especially I would say here during covid times here. Yeah.
You know security truly is top of mind for a lot of organizations. And the fact miters out with this. You know, that's a good thing.
It's a good thing. Anyway, I would have to agree. I think we're starting to see a lot of signs that security is taking a little bit more seriously and that might be as you mentioned as a result of or breaches and more exposure, but they were starting to see more Security smes on boards.
Now, we're starting to see, you know, these the ciso role, you know, interacting with words a lot more and I think that's a very positive sign for for, you know Direction. agreed All right, let's jump in back into the company though. You guys recently last month?
Well before we get into the release last month 2019 come up with the you realize this is an issue you're working on it. When did the company actually launch or come out of stealth or however, the police term is today, sir, sir? Yeah, we found it back in March of this year 2022 and then we raised our seed rounds majority of it in April and then we finished raising that round by June came out of stealth just before black hat this year and why so we've been we've been going at it since March sort of full time as dedicated teams.
We've grown relatively quickly. We're up to 18 employees now and really again those specialist kind of bridging that gap between, you know, we have some adversarial machine learning Specialists. We have some cyber security Specialists on the threat intelligence and reverse engineering side, and we're really working at all angles of security when it comes to artificial intelligence machine learning assets, which means a lot of Ask that's that's involved in some of these attacks as well as a lot of the adjacent code and some of the libraries and repositories that are kind of power.
Ing, so we really want to take a holistic approach to protecting every stage of the machine learning operations lifecycle and that sort of brings us to date. I think we've got Some fantastic research that's written for for multiple audiences. We've got some some kind of see so level stuff and some deep technical stuff.
So for anybody who's interested that that sort of our goal right now is the education side. We want to make sure that we're we're kind of teaching everybody what this problem is how it came to be. You know why we're why were there and and what the steps are going to have to take to make sure that we're securing ourselves, but I think that brings us to date.
Excellent, man. All right. So just about a month ago You released.
The platform where a platform or how do you refer to it? Yeah, we call it the ml SEC platformer machine learning security platform and that's right at the moment. It's three different products and again as as I mentioned sort of there's that ml life cycle.
So you have sort of your data side of that where you're where your sourcing curating your data. You have your model sort of training and development life cycle as part of that as well. And then you're deployment stage where your model is is interacting with your product your production systems and there's sort of the validation and redeployment and all those components and we want to make sure that we're securing every every step of that.
So we have three components of that. Ml psych platform. We have sort of the the Integrity solution that we call our ml model scanner and this is really important because at the moment there really isn't a way to check the Integrity of your model before this tool when you think about sort of insecurity, we do a lot way of guaranteeing a file or hearing some sort of structure that has not been compromised, but in machine learning that's a little bit more difficult to do because these models learn and grow and develop they're not, you know a static entity.
So we had to build a little bit more. Collects of a solution to be able to scan a machine learning model and guarantee either something that you home grew is, you know from a known good state has not been altered or a lot of organizations. These days are engaged in like a transfer learning scenario where they're either pulling down an open source model of from something like openai or hugging phase.
Or their purchasing a free-trained model from from an organization. So for instance, if you know these organizations don't have the training sets to be able to build all these models from the ground up. They might be purchasing them.
So it becomes extremely important to guarantee that that model is what you expected to be and then we're all so seeing attacks where people are actually injecting malicious code in the models and we're gonna be actually showing how easy that is to do. It's some upcoming events here in the near future some of the some major conferences. We'll be talking about it as well where you could even want France somewhere through models turn them into reverse shells.
They're highly vulnerable at the code levels. Well, so that sort of that that initial kind of integrity and then our Flagship is is actually it's it's an evolution of detection and response. So we call it machine learning detection and response or mldr.
And this actually protects the model in real time. And and this is really important because we wanted to take an approach a little bit different than some others have done. If you really look at the academic way that some models have been protected in the past.
It's through what's called robustness or complexity essentially. It's it's a like injecting noise in your model to make it really big in robust and harder to Traverse and harder to infer and that was a good first step. But today there's automated attack tools that can do this and you know that attack on silence back in 2 2019.
I took about 40 days and when we got back to look at the forensics of what was going on today, you can download an automated to love GitHub and conducted about 10 seconds. So all that sort of noise injection doesn't represent that much barrier anymore. And so it was also a pretty invasive technique like they would require those inside your organization to be working on your model or if you want to work with the third party image you had to give them a lot of access, you're all your raw data your algorithms themselves.
Well, we didn't love that approach. We wanted to create a product that could protect a model without having to get inside. So we actually measured the way that users are requesters of the model interact with it.
And with the that day we can actually look at mathematical patterns to identify whether or not somebody who's using your model as they should be or whether they're reversing it or tampering with it or engagement. So that's that kind of Flagship product. That's a real-time protection.
And then lastly we have a observability tool that we can use to audit all of your security, you know posture across your entire organization or if you're Distributing your models, like you're you're a seller of those pre-trained models. You can actually keep track of them in other organizations as well. So it's really it's a holistic platform to protect against all of those stages and really ensure that the entire data science, you know commitment from the from all of the resources across the organizations here.
I love it. Let's talk a little bit. Just kind of go to market how.
I was one engage. With the company and deploy this stuff. Yeah, absolutely.
We try and make that as easy as possible because this is a it's really by Nature because it's a little bit of a security issue. It's a little bit of a data science issue. We want to make sure we consolidate that as much as possible.
So we our goal was to make sure that we were empowering. Security Personnel to protect these ml assets without having to have a deep understanding it. So the tool actually integrates with Sim tools that are already, you know being used by most organizations.
So like it's your one sock operator can use our product in our products API in their own workflow to protect those ml assets and then when they start seeing patterns or they start seeing something they need to escalate the data science team. They can do that through the tool as well. So the reason I sort of set the stage like that is because this isn't something that could be of interest to a see so who wants to purchase it as part of their security platform or a chief data scientist who wants to protect their their output it protect the the Integrity of their of their models going into production systems.
But either way it's the same way to get a hold of us. com and ask for a demo. You can reach out to me.
Yeah and reach out to anybody else on our team as well and we can set that up for you. We also offer some services on the educational side so we can do some red teaming we can do some bread assessing to kind of let you know. Hey across all of your assets.
Here's Your you know in some individualized, you know support around, you know here is where you know, you're probably the most exposed or depending on you know, what what your technology looks like where you should focus your efforts and your resources and then we can do some education there some trainings and that ultimately can lead into using the platform itself. com, but you know, you're absolutely welcome to kind of get a hold of us any way you can and we'll make sure that we're helping protect your resources. Very cool.
Hey, I love this Tito. Yeah, I'll be honest with you. I haven't.
Spoken to anybody or a company who? Who is out in front on this problem like you guys have so you know it's always great to be first mover and and kind of Define that market but it sounds like this is something you guys have been watching now for two three years. And yeah time is come.
Yeah, I would say you know that the data Science World. This is not new. They've been charged, you know, they've been publishing white papers on adversarial attacks since 2013 as far back as I can find.
So this is sort of like when we talked to a mature data science team, they know have honorable they are this isn't really news to them. They just sort of have been doing what they've been you know sanctions to do and so I think I think the security world. This is a little bit more of a wake up call.
We're organizations. I mean, I think that you know, we sort of seen that pattern like new emerging technology new dedicated products where in that really is why the Cecil role is sort of so, you know expansive and complex at this moment because there really is a lot of different elements your organization that Protect but machine learning is really no different. You know, I think the advice I give to see says is not to treat it any differently than any other newer technology over the last decade of your career.
You've probably gone through this 20 times. You need to understand sort of you're gonna require some dedicated resources protect. I think the only difference is just how far and fast.
We're committing as a society to artificial intelligence and then machine learning assets. I think PWC actually predicts that by 2030 Aai is going to be almost 16 trillion dollars of the market. I think that's gonna be roughly 13% of the global economy at that point.
So when you think about just how fast we're moving towards this technology in every use case every industry every company these days a big data company and they're all taking advantage of machine learning to you know, make product decisions to make real-time pipeline decisions as well. As you know, historical analysis on all that data. I mean this technology is all over the place.
So the fact that it's it's not secure is really going to be it already is it's going to continue to be a major sort of exposure in our in our defense. So I think that that would be really it's a similar pattern. It's just we're hitting an area of deployment that we've ever seen before in terms of how committed we are to this technology.
You bet. Hey just before we go. com.
It's one word. Oh one more single layer. Yeah.
Okay Tito best of luck with hidden layer. Hey, man, he puts posted you're invited back any time. Thank you so much.
See this would be an interesting area to watch. I I unfortunately I have a feeling. You know, we'll see stuff Brewing up here.
So I think you're absolutely right on. Thank you so much for the time today. My pleasure.
All right, Chris Tito secito saido from hidden layer on textrung TV. We're gonna take a break. We'll be right back.