For several weeks now, technologists in the U.S. have been drumming up support for more open-weight AI model launches in order to keep ahead of China’s AI, even as they weigh up the security risks of models that users can modify and run independently.While regulatory debates strongly differentiate between closed and open-weight models, Shane Huntley, CTO and Senior Director at Google’s Threat Intelligence Group, challenged this black-and-white approach when thinking about AI cyber-attacks and cyber-defence.In an interaction with The Hindu, Mr. Huntley said that he had been tracking with great interest the news stories about AI models going rogue, observing that every month saw something happening in AI that would have “felt like science fiction a month before.”“So, I certainly think that the models and what we saw here with these attacks are a real threat. It just shows how much investment in AI safety is important, in alignment, in making sure we actually have close control,” he explained.Mr. Huntley believed that the AI ecosystem would support both open and closed models for a long time, similar to how tech users today can choose between open-source and closed-source software.“I think the open models do show us that these capabilities are going to be out there; this is not a technology that we can fully constrain. They can’t just control how these hackers use AI, via controlling the environment,” Mr. Huntley said.He added that Google ensured its models were used on the defence side first, and that the company collaborated with good faith actors to address their vulnerabilities before a broader model release. Noting that Google released both closed models (like Gemini) as well as open-weight models (like Gemma), Mr. Huntley said it was not a “black-and-white situation.”AI attackers for all?The Google executive observed that when an AI cyber-attack takes place, pinpointing which model version or agent or hardware or open/closed model provider was involved, can be difficult at times. This is increasingly the case as the hardware required to run sophisticated models can now be bought by everyday users at their local stores.“If we see somebody doing an automated attack, can we really tell if it’s running in a data centre somewhere, or if it’s running in somebody’s local machine, or somewhere else? There’s just so many models out there. So, it’s such an explosion of capability here. And we’re certainly seeing very imaginative use,” Mr. Huntley remarked.Regarding some agentic attacks, Mr. Huntley said there were incidents where people connected models to open source attacking tools and then automated their attacks in order to go after different victims.In other words, attackers are using a range of tools — both open and closed — to carry out cyber crimes.“And I think one of the other things we really see is the speed, right? The scale. We’re seeing attackers that, you know, operate at one level of speed suddenly able to automate and operate at a much bigger range of speed,” Mr. Huntley said.“We need to be doing defence at computer speed,” he added.Diverse range of targetsAmongst multiple hostile states, Mr. Huntley said Russia had been a formidable and comprehensive threat actor for years, and would be for years to come. Other threat actors that his group focuses on include Iran and North Korea.Apart from cyber-attacks targeting senior levels of the government or crucial infrastructure systems, many state-backed attackers are also exploiting AI to carry out cyber crimes. These can take the forms of highly customised social engineering (impersonation) attacks, ransomware, phishing scams, and even employment scams that affect individual users.The first line of defence is often the intended victim’s email protections. That is where Google comes in.“One of the first biggest uses of machine learning and artificial intelligence were actually the spam filters of Gmail, right? We have a long history of using AI and machine learning for defence. And so, it’s always this equilibrium between attackers and defenders,” said Mr. Huntley.Pending AI regulationsUsers naturally look to their regulators in order to address these fast-growing AI threats. Striking a cautious but measured note, Mr. Huntley called for the careful application of laws governing AI and AI companies.“In one of the ways, the worst possible world would be, like, if we over-regulate the good guys so they can’t actually use this [AI] to do defence, but then the attackers operating out of other countries with less regulations, are able to use it on the attacking side. . .then we haven’t made the world better,” Mr. Huntley said.He pointed out that people in general had a tendency to focus a lot more on the threats of AI, rather than the benefits of the technology. Mr. Huntley acknowledged that he too found himself having to throw away almost everything he knew about AI every few months, due to its pace of change and advancement.As a warning, Mr. Huntley cited the example of people who last used AI months or years ago, allowing a hallucinated answer or a failed prompt to define their understanding of the technology as a whole.He encouraged users to ask more questions about AI. For example: what can it do now? How have things changed? What is new? What is happening?“I’ve never seen a technology move this fast,” Mr. Huntley said. “How fast things are changing now makes the dot-com boom seem slow, right? What we have today is wholly different from six months ago [...] There’s always the hot topic of the day, like the frontier models going rogue in other places; I think it’s a super interesting topic, but it’s also one that we need to report on in a nuanced way as well. It’s so complicated.”
We need to be doing defence at computer speed, says Google Threat Intelligence Group’s Senior Director
Full Article
Original Source
Read the full article at Thehindu →KhanList aggregates and links to publicly available news content. We do not host full articles from third-party sources. Always verify important information with original sources.