{"id":3453,"date":"2024-05-03T09:29:53","date_gmt":"2024-05-03T14:29:53","guid":{"rendered":"https:\/\/www.darkreading.com\/cyber-risk\/reducing-ai-risks-requires-visibility-and-better-planning"},"modified":"2024-05-03T09:29:53","modified_gmt":"2024-05-03T14:29:53","slug":"feds-reducing-ai-risks-requires-visibility-better-planning","status":"publish","type":"post","link":"https:\/\/ddi.mohflo.net\/index.php\/2024\/05\/03\/feds-reducing-ai-risks-requires-visibility-better-planning\/","title":{"rendered":"Feds: Reducing AI Risks Requires Visibility &amp; Better Planning"},"content":{"rendered":"<div class=\"media_block\"><a href=\"https:\/\/i0.wp.com\/eu-images.contentstack.com\/v3\/assets\/blt6d90778a997de1cd\/bltdb41969a4dd77d2b\/6634f4ba324f702c0ed0732b\/Deemerwha_studio-AI-tools-shutterstock.jpg?ssl=1\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/feds-reducing-ai-risks-requires-visibility-better-planning.jpg?w=640&#038;ssl=1\" class=\"media_thumbnail\"><\/a><\/div>\n<div><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/feds-reducing-ai-risks-requires-visibility-better-planning.jpg?w=640&#038;ssl=1\" class=\"ff-og-image-inserted\"><\/div>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">When the US Department of Energy (DoE) analyzed the use of artificial intelligence and machine learning (AI\/ML) models in critical infrastructure last month, the agency came up with a top 10 list of potential beneficial applications of the technology, including simulations, predictive maintenance, and malicious-event detection.&nbsp;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Predictably, the DoE also came up with <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.energy.gov\/articles\/doe-announces-new-actions-enhance-americas-global-leadership-artificial-intelligence\" rel=\"noopener\">four broad categories of risk<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">: unintentional failure modes, adversarial attacks against AI, hostile applications of AI, and compromise of the AI supply chain.&nbsp;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The DoE is not alone \u2014 the Biden administration is driving an extensive government assessment of the benefits and risks of using AI, especially in the critical infrastructure networks. On May 3, for example, the Department of Transportation <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.federalregister.gov\/documents\/2024\/05\/03\/2024-09645\/opportunities-and-challenges-of-artificial-intelligence-ai-in-transportation-request-for-information\" rel=\"noopener\">issued a request for information<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> asking for interested parties to describe both the benefits and dangers of AI to the transportation system. On April 29, the Department of Homeland Security (DHS) <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.dhs.gov\/news\/2024\/04\/29\/dhs-publishes-guidelines-and-report-secure-critical-infrastructure-and-weapons-mass\" rel=\"noopener\">spelled out its own take<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, describing three broad categories of risk: attacks using AI, attacks targeting AI systems, and failure of design or implementation.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Yet the DHS also gave broad recommendations on how organizations can mitigate the risk of AI, focusing on a four-part strategy: governing by creating policy and a culture of risk management, mapping all the current assets or services using AI, measuring by monitoring the ongoing usage of AI, and managing by implementing a risk management strategy.&nbsp;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">It&#8217;s a good, broad overview of what organizations need to do to mitigate AI risk, but it&#8217;s just a start, says Malcolm Harkins, chief security and trust officer at HiddenLayer, an AI risk management firm.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;If you look at this like a book, they&#8217;re great chapters \u2014 great macro business processes,&#8221; he says. &#8220;The real success or failure will become the depth of [your approach], and then the efficacy and efficiency with which you do it.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">A variety of risks have already targeted organizations. Malicious AI\/ML models <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cloud-security\/ml-model-repositories-next-big-supply-chain-attack-target\" rel=\"noopener\">hosted on Hugging Face and other repositories<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> have demonstrated the potential of attacks through the supply chains, as described by the DoE. Indirect prompt-injection attacks against ChatGPT and other large language models (LLMs) have demonstrated that <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/application-security\/chatgpt-other-generative-ai-apps-prone-to-compromise-manipulation\" rel=\"noopener\">the most promising AI models could be co-opted or corrupted by attackers<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, as highlighted by the DHS.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Attackers are also widely experimenting with AI models to make their operations more efficient and their attacks \u2014 especially phishing attacks \u2014&nbsp;more effective.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"(Try to) Ignore the AI Hype &amp; Start Small\">(Try to) Ignore the AI Hype &amp; Start Small<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">For organizations, the growing use of AI means growing exposure to the risks. Organizations won&#8217;t be able to avoid adopting AI\/ML models: Even if they are not rushing to adopt AI in their own operations, an increasing number of products include \u2014 or at least claim to include \u2014&nbsp;AI features.&nbsp;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">In its report, &#8220;<\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.dhs.gov\/sites\/default\/files\/2024-04\/24_0426_dhs_ai-ci-safety-security-guidelines-508c.pdf\" rel=\"noopener\">Safety and Security Guidelines for Critical Infrastructure Owners and Operators<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">,&#8221; the DHS describes AI risk management in terms of a framework of ongoing processes for that Map, Measure, and Manage exposure to AI in the business, with an overarching Govern function that regulates activities.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">For many companies, the Map and Measure parts of the DHS mitigation strategy will initially be the most important, HiddenLayer&#8217;s Harkins says.&nbsp;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;I&#8217;m a former finance procurement guy \u2014&nbsp;I need an inventory; I need to discover the assets to manage,&#8221; he says. &#8220;Where is AI in use? Where am I getting it from a third party because they&#8217;ve started incorporating into the technology they provided to me, and then how do I ask the right questions of my third-party risk management to make sure they&#8217;ve done it right?&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Mapping involves identifying all the uses of AI in the organization&#8217;s environment, documenting the possible safety and security risks of those implementations, and reviewing third-party supply chains for AI risk. Measuring focuses on defining metrics to detect and manage AI risk, as well as the continuous monitoring of AI implementations.&nbsp;<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Operational Technology Requires More Strict Controls\">Operational Technology Requires More Strict Controls<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The DHS paper focuses specifically on critical infrastructure owners and operators, which consider AI models and platforms as possible solutions to solve long-standing challenges, such as logistics and cyber defense, with the top AI use categories including operational awareness, performance optimization, and automation of operations.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Using AI in the world of operational technology means that companies have to worry about the secure transfer of data into the cloud because \u2014 while smaller ML models can run on-premises \u2014 the most advanced AI models are run in the cloud as a service, says Phil Tonkin, field CTO for Dragos, a provider of cybersecurity for critical infrastructure.&nbsp;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Thus, organizations need to minimize the amount of data sent to the cloud, secure those communications, and monitor the connection for anomalous behavior that could indicate malicious activity, he says.&nbsp;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;While you may establish trust between that AI service and the OT system, you still have potential risks that may come down through those now-trusted links,&#8221; Tonkin says. &#8220;So monitoring all of the traffic, in and out, is the one the way to do it.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The DHS has already implemented, or is in the process of implementing, AI in <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.dhs.gov\/news\/2024\/04\/29\/fact-sheet-dhs-facilitates-safe-and-responsible-deployment-and-use-artificial\" rel=\"noopener\">four pilot programs<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">.&nbsp;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The Cybersecurity and Infrastructure Security Agency has already completed a pilot using AI cybersecurity systems to detect and remediate software vulnerabilities in critical infrastructure and US government systems. DHS also announced it would be using an AI platform to help the Homeland Security Investigations agency investigating fentanyl distribution and child sexual exploitation, and the Federal Emergency Management Agency plans to use AI to support communities in developing plans for mitigating risks and improving resilience. Finally, the United States Citizenship and Immigration Services plans to use AI to improve officer training.<\/span><\/p>\n<p><a href=\"https:\/\/www.darkreading.com\/cyber-risk\/reducing-ai-risks-requires-visibility-and-better-planning\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>When the US Department of Energy (DoE) analyzed the use<\/p>\n","protected":false},"author":12,"featured_media":3454,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1],"tags":[809],"class_list":["post-3453","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-dark-reading"],"featured_image_urls":{"full":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/feds-reducing-ai-risks-requires-visibility-better-planning.jpg?fit=1600%2C900&ssl=1",1600,900,false],"thumbnail":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/feds-reducing-ai-risks-requires-visibility-better-planning.jpg?resize=150%2C150&ssl=1",150,150,true],"medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/feds-reducing-ai-risks-requires-visibility-better-planning.jpg?fit=300%2C169&ssl=1",300,169,true],"medium_large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/feds-reducing-ai-risks-requires-visibility-better-planning.jpg?fit=640%2C360&ssl=1",640,360,true],"large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/feds-reducing-ai-risks-requires-visibility-better-planning.jpg?fit=640%2C360&ssl=1",640,360,true],"1536x1536":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/feds-reducing-ai-risks-requires-visibility-better-planning.jpg?fit=1536%2C864&ssl=1",1536,864,true],"2048x2048":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/feds-reducing-ai-risks-requires-visibility-better-planning.jpg?fit=1600%2C900&ssl=1",1600,900,true],"chromenews-featured":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/feds-reducing-ai-risks-requires-visibility-better-planning.jpg?fit=1024%2C576&ssl=1",1024,576,true],"chromenews-large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/feds-reducing-ai-risks-requires-visibility-better-planning.jpg?resize=825%2C575&ssl=1",825,575,true],"chromenews-medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/feds-reducing-ai-risks-requires-visibility-better-planning.jpg?resize=590%2C410&ssl=1",590,410,true]},"author_info":{"display_name":"Dark Reading","author_link":"https:\/\/ddi.mohflo.net\/index.php\/author\/darkreading\/"},"category_info":"<a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/uncategorized\/\" rel=\"category tag\">Uncategorized<\/a>","tag_info":"Uncategorized","comment_count":"0","jetpack_featured_media_url":"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/feds-reducing-ai-risks-requires-visibility-better-planning.jpg?fit=1600%2C900&ssl=1","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/3453","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/comments?post=3453"}],"version-history":[{"count":0,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/3453\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media\/3454"}],"wp:attachment":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media?parent=3453"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/categories?post=3453"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/tags?post=3453"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}