Cybersecurity Policy Report, ‘Five Eyes’ Allies Warn of AI Security Threats, (Apr 16, 2024)
The rapid development of artificial intelligence systems has created new opportunities for malicious cyber actors to steal data or “poison” the datasets used to train AI systems, according to the U.S. and its “Five Eyes” allies—Australia, Canada, New Zealand, and the United Kingdom.
“The rapid adoption, deployment, and use of AI capabilities can make them highly valuable targets for malicious cyber actors. Actors, who have historically used data theft of sensitive information and intellectual property to advance their interests, may seek to co-opt deployed AI systems and apply them to malicious ends,” the nations’ cyber defense agencies said in a joint advisory published yesterday.
“Malicious actors targeting AI systems may use attack vectors unique to AI systems, as well as standard techniques used against traditional IT. Due to the large variety of attack vectors, defenses need to be diverse and comprehensive. Advanced malicious actors often combine multiple vectors to execute operations that are more complex. Such combinations can more effectively penetrate layered defenses,” the advisory says.
The advisory recommends, among other things, that organizations develop and maintain AI systems in secure environments, actively monitor them for threats, and adopt “zero-trust” principles that require authentication of any device or user accessing the AI system.
“In the end, securing an AI system involves an ongoing process of identifying risks, implementing appropriate mitigations, and monitoring for issues. By taking the steps outlined in this report to secure the deployment and operation of AI systems, an organization can significantly reduce the risks involved,” the advisory says.
“These steps help protect the organization’s intellectual property, models, and data from theft or misuse,” it adds. “Implementing good security practices from the start will set the organization on the right path for deploying AI systems successfully.”
News: FederalLegislation InternationalLegislation DataSecurity