{"id":2641,"date":"2024-03-01T21:04:39","date_gmt":"2024-03-01T21:04:39","guid":{"rendered":"https:\/\/www.darkreading.com\/cyber-risk\/do-you-know-where-your-ai-models-are-tonight"},"modified":"2024-03-01T21:04:39","modified_gmt":"2024-03-01T21:04:39","slug":"its-10-p-m-do-you-know-where-your-ai-models-are-tonight","status":"publish","type":"post","link":"https:\/\/ddi.mohflo.net\/index.php\/2024\/03\/01\/its-10-p-m-do-you-know-where-your-ai-models-are-tonight\/","title":{"rendered":"It&#8217;s 10 p.m. Do You Know Where Your AI Models Are Tonight?"},"content":{"rendered":"<div class=\"media_block\"><a href=\"https:\/\/i0.wp.com\/eu-images.contentstack.com\/v3\/assets\/blt6d90778a997de1cd\/blt39910294ff00e951\/65e245da27df54040a108e7f\/time-robot-Kirsty-Pargeter-alamy.jpg?ssl=1\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/03\/its-10-p-m-do-you-know-where-your-ai-models-are-tonight.jpg?w=640&#038;ssl=1\" class=\"media_thumbnail\"><\/a><\/div>\n<div><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/03\/its-10-p-m-do-you-know-where-your-ai-models-are-tonight.jpg?w=640&#038;ssl=1\" class=\"ff-og-image-inserted\"><\/div>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">If you thought the software supply chain security problem was difficult enough today, buckle up. The explosive growth in AI use is about to make those supply chain issues exponentially harder to navigate in the years to come.&nbsp;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Developers, application security pros and DevSecOps professionals are called to fix the highest risk flaws that lurk in what seems like the endless combinations of open source and proprietary components that are woven into their applications and cloud infrastructure. But it&#8217;s a constant battle trying to even understand which components they have, which ones are vulnerable, and which flaws put them most at risk. Clearly, they&#8217;re already struggling to sanely manage these dependencies in their software as it is.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">What&#8217;s going to get harder is the multiplier effect that AI stands to add to the situation.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"AI Models as Self-Executing Code\">AI Models as Self-Executing Code<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">AI and machine learning (ML)-enabled tools are software just the same as any other kind of application\u2014and their code is just as likely to suffer from supply chain insecurities. However, they add another asset variable to the mix that greatly increases the attack surface of the AI software supply chain: AI\/ML models.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;What separates AI applications from every other form of software is that it relies in some way or fashion on a thing called a machine learning model,&#8221; explains Daryan Dehghanpisheh, co-founder of Protect AI. &#8220;As a result, that machine learning model itself is now an asset in your infrastructure. When you have an asset in your infrastructure, you need the ability to scan your environment, identify where they are, what they contain, who has permissions, and what they do. And if you can&#8217;t do that with models today, you can&#8217;t manage them.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">AI\/ML models provide the foundation for an AI system&#8217;s ability to recognize patterns, make predictions, make decisions, trigger actions, or create content.&nbsp; But the truth is that most organizations don&#8217;t even know how to even start gaining visibility into all of the AI models embedded in their software. Models and the infrastructure around them are built differently than other software components and traditional security and software tooling isn&#8217;t built to scan for or to understand how AI models work or how they&#8217;re flawed. This is what makes them unique, says Dehghanpisheh, who explains that they&#8217;re essentially hidden pieces of self-executing code.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;A model, by design, is a self-executing piece of code. It has a certain amount of agency,&#8221; says Dehghanpisheh. &#8220;If I told you have assets all over your infrastructure that you can&#8217;t see, you can&#8217;t identify, you don&#8217;t know what they contain, you don&#8217;t know what the code is, and they self-execute and have outside calls, that sounds suspiciously like a permission virus, doesn&#8217;t it?&#8221;<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"An Early Observer of AI Insecurities\">An Early Observer of AI Insecurities<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Getting ahead of this issue was the big impetus behind him and his co-founders launching Protect AI in 2022, which is one of a spate of new firms cropping up to address model security and data lineage issues that are looming in the AI era. Dehghanpisheh and co-founder Ian Swanson, saw a glimpse of the future when they worked previously together building AI\/ML solutions at AWS. Dehghanpisheh was the global leader for AI\/ML solution architects at the firm.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;During the time that we spent together at AWS we saw customers building AI\/ML systems at an incredibly rapid pace long before generative AI captured the hearts and minds of everyone from the C-suite to Congress,&#8221; he says, explaining that he worked with a range of engineers and business development experts, and also worked with customers extensively. &#8220;That&#8217;s when we realized how and where the security vulnerabilities unique to AI\/ML systems are.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">He says that they observed three basic things about AI\/ML that had incredible implications for the future of cybersecurity. The first was that the pace of adoption was so fast that they saw firsthand how quickly shadow IT entities were cropping up around AI development and business use that escaped the kind of governance that would oversee any other kind of development in the enterprise.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The second was that the majority of tools that were being used\u2014whether commercial or open source\u2014were built by data scientists and up-and-coming machine learning engineers who had never been trained in security concepts.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;As a result, you had really useful, very popular, very distributed, widely adopted tools that weren&#8217;t built with a security-first mindset,&#8221; he says.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"AI Systems Not Built 'Security-First'\">AI Systems Not Built &#8216;Security-First&#8217;<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">As a result, many AI\/ML systems and shared tools lack the basics in authentication and authorization and often grant too much read and write access in file systems, he explains. Coupled with insecure network configurations and then those inherent problems in the models and organizations start getting bogged down cascading security issues in these highly complex, difficult to understand systems.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;That made us realize that the existing security tools, processes, frameworks, no matter how shift left you went, were missing the context that machine learning engineers, data scientists, and AI builders would need,&#8221; he says<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Finally, the third major observation he and Swanson made during those AWS days was that AI breaches weren&#8217;t coming. They had already arrived.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;We saw customers have breaches on a variety of AI\/ML systems that should have been caught, but weren&#8217;t,&#8221; he says. &#8220;What that told us do is that the set and the processes, as well as the incident response management elements, were not purpose-built for the way AI\/ML was being architected. That problem has became much worse as generative AI picked up momentum&#8221;<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"AI Models Are Widely Shared\">AI Models Are Widely Shared<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Dehghanpisheh and Swanson also started seeing how models and training data were creating a unique new AI supply chain that would need to be considered just as seriously as the rest of the software supply chain. Just like with the rest of modern software development and cloud-native innovation, data scientists and AI experts have fueled advancements in AI\/ML systems through rampant use of open source and shared componentry\u2014including AI models and the data used to train them. So many AI systems\u2014whether academic or commercial\u2014are built using someone else&#8217;s model. And like with the rest of modern development, the explosion in AI development keeps driving a huge daily influx of new model assets proliferated across the supply chain, which means keeping track of them all just keeps getting harder.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Take Hugging Face, for example. This is one of the most widely used repositories of open source AI models online today\u2014its founders say they want to be the GitHub of AI. Back in November 2022, Hugging Face users had shared 93,501 different models with the community. A year later, in November 2023, that had blown up to 414,695 models. Just three months later, that number has expanded to 527,244. This is an issue whose scope is snowballing by the day. And it is going to put the software supply chain security problem &#8216;on steroids,&#8217; says Dehghanpisheh.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">A <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a href=\"https:\/\/protectai.com\/threat-research\/hugging-face-analysis\" target=\"_self\" rel=\"sponsored noopener\" class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\">recent analysis<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> by his firm found thousands of models that are openly shared on Hugging Face that can execute arbitrary code on model load or inference. While Hugging Face does some basic scanning of its repository for security issues, there are many models missed along the way\u2014at least half of the highly risk models discovered in the research were not deemed unsafe by the platform and Hugging Face makes it clear in documentation that determining the safety of a model is ultimately the responsibility of its users.&nbsp;<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Steps for Tackling AI Supply Chain\">Steps for Tackling AI Supply Chain<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Dehghanpisheh believes the lynchpin of cybersecurity in the AI era will start first by creating a structured understanding of AI lineage. That includes model lineage and data lineage, which are essentially the origin and history of these assets, how they&#8217;ve been changed, the metadata associated with them.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;That&#8217;s the first place to start. You can&#8217;t fix what you can&#8217;t see and what you can&#8217;t know and what you can&#8217;t define, right?&#8221; he says.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Meantime, on the daily operational level he believes organizations need to build out capabilities to scan their models, looking for flaws that can impact not only the hardening of the system but the integrity of its output. This includes issues like AI bias and malfunction that could cause real-world physical harm from, say, an autonomous car crashing into a pedestrian.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;The first thing is you need to scan,&#8221; he says. &#8220;The second thing is you need to understand those scans. And the third is then once you have something that&#8217;s flagged, you essentially need to stop that model from activating. You need to restrict its agency.&#8221;<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"The Push for MLSecOps\">The Push for MLSecOps<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">MLSecOps is a vendor-neutral movement that mirrors the DevSecOps movement in the traditional software world.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;Similar to the move from DevOps to DevSecOps, you&#8217;ve got to do two things at once. The first thing you&#8217;ve got to do is make the practitioners aware that security is a challenge and that it is a shared responsibility,&#8221; he says. &#8220;The second thing you&#8217;ve got to do is give context and put security into tools that keep data scientists, machine learning engineers, AI builders on the bleeding edge and constantly innovating, but allowing the security concerns to disappear into the background.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">In addition, he says organizations are going to have to start adding governance, risk and compliance policies and enforcement capabilities and incident response procedures that help govern the actions and processes that take place when insecurities are discovered. This means like with a solid DevSecOps ecosystem, MLSecOps will need strong involvement from business stakeholders all the way up the executive ladder.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The good news is that AI\/ML security is benefiting from one thing that no other rapid technology innovation has had right out of the gate\u2014namely, regulatory mandates right out of the gate.&nbsp;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;Think about any other technology transition. Name one time that a federal regulator or even state regulators have said this early on, &#8216;Whoa, whoa, whoa, you&#8217;ve got to tell me everything that&#8217;s in it. You&#8217;ve got to prioritize knowledge of that system. You have to prioritize a bill of materials,'&#8221; he says. &#8220;There isn&#8217;t any.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">This means that many security leaders are more likely to get buy-in to build out AI security capabilities a lot earlier in the innovation lifecycle.&nbsp; One of the most obvious signs of this support is the rapid shift to sponsor new job functions at organizations.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8221; The biggest difference that the regulatory mentality has brought to the table is that in January of 2023, the concept of a director of AI security was novel and didn&#8217;t exist. But by June, you started seeing those roles,&#8221; he says. &#8220;Now, they&#8217;re everywhere and they&#8217;re funded.&#8221;<\/span><\/p>\n<p><a href=\"https:\/\/www.darkreading.com\/cyber-risk\/do-you-know-where-your-ai-models-are-tonight\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>If you thought the software supply chain security problem was<\/p>\n","protected":false},"author":12,"featured_media":2642,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1],"tags":[809],"class_list":["post-2641","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-dark-reading"],"featured_image_urls":{"full":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/03\/its-10-p-m-do-you-know-where-your-ai-models-are-tonight-scaled.jpg?fit=2560%2C1440&ssl=1",2560,1440,false],"thumbnail":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/03\/its-10-p-m-do-you-know-where-your-ai-models-are-tonight-scaled.jpg?resize=150%2C150&ssl=1",150,150,true],"medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/03\/its-10-p-m-do-you-know-where-your-ai-models-are-tonight-scaled.jpg?fit=300%2C169&ssl=1",300,169,true],"medium_large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/03\/its-10-p-m-do-you-know-where-your-ai-models-are-tonight-scaled.jpg?fit=640%2C360&ssl=1",640,360,true],"large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/03\/its-10-p-m-do-you-know-where-your-ai-models-are-tonight-scaled.jpg?fit=640%2C360&ssl=1",640,360,true],"1536x1536":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/03\/its-10-p-m-do-you-know-where-your-ai-models-are-tonight-scaled.jpg?fit=1536%2C864&ssl=1",1536,864,true],"2048x2048":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/03\/its-10-p-m-do-you-know-where-your-ai-models-are-tonight-scaled.jpg?fit=2048%2C1152&ssl=1",2048,1152,true],"chromenews-featured":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/03\/its-10-p-m-do-you-know-where-your-ai-models-are-tonight-scaled.jpg?fit=1024%2C576&ssl=1",1024,576,true],"chromenews-large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/03\/its-10-p-m-do-you-know-where-your-ai-models-are-tonight-scaled.jpg?resize=825%2C575&ssl=1",825,575,true],"chromenews-medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/03\/its-10-p-m-do-you-know-where-your-ai-models-are-tonight-scaled.jpg?resize=590%2C410&ssl=1",590,410,true]},"author_info":{"display_name":"Dark Reading","author_link":"https:\/\/ddi.mohflo.net\/index.php\/author\/darkreading\/"},"category_info":"<a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/uncategorized\/\" rel=\"category tag\">Uncategorized<\/a>","tag_info":"Uncategorized","comment_count":"0","jetpack_featured_media_url":"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/03\/its-10-p-m-do-you-know-where-your-ai-models-are-tonight-scaled.jpg?fit=2560%2C1440&ssl=1","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/2641","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/comments?post=2641"}],"version-history":[{"count":0,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/2641\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media\/2642"}],"wp:attachment":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media?parent=2641"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/categories?post=2641"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/tags?post=2641"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}