Why we need cybersecurity of AI: ethics and responsible innovation

(Credit: Unsplash)

This article is brought to you thanks to the collaboration of The European Sting with the World Economic Forum.

Author: Sadie Creese, Professor of Cybersecurity, University of Oxford


There are now many new AI-specific risks.Whenever we observe a new technology trend, we can expect harm potential to arise and opportunities for threats to monetize our use of technology.This blog is part of an Agenda series from the AI Governance Alliance, which advocates for responsible global design, development and deployment of inclusive AI systems.

With the growing use of advanced deep machine learning, AI must be deployed alongside a responsibility for ensuring the integrity, safety and security of such systems.

New risks

There has been much debate and discussion about new AI-specific risks. A key example of this is the potential for a lack of fairness or the presence of bias in systems utilizing AI. This is based on their initial training data or on how we maintain the AI model as the system evolves and learns from its environment. Other concerns surround a lack of ability to scrutinize, check the integrity of systems and maintain an alignment with our value sets – often due to challenges in understanding how the AI system reached its outputs, exasperated in situations where outputs are unreliable.

There are also new ways of compromising organizations by attacking the AI system itself. Various vulnerabilities are already known. It is possible to influence the learning via the datasets used for training and model evolution, so producing different models that are potentially unsafe or simply misaligned and acting according to the will of threat actors.

But the vulnerability of AI systems won’t be limited to risks of data-poisoning or unsafe model shifts, we will also encounter the kinds of run-time software errors that have constantly undermined our computing systems since their inception. If the AI environment is compromised, then such errors will provide opportunities for attackers to take control of the local computer and use it as a platform from which to move throughout the wider business infrastructure. Ultimately, as with any other kind of digital system, the range of potential harms will be driven by the contexts of use. In the case of AI, this range is large and growing and will certainly include systems that are within our critical infrastructures and potentially even risking human life. They will reach into the influence of people and societies, potentially impacting human agency and democratic processes, as well as governance of sectors and business.

A growing cyber threat

Examples of AI-system vulnerability and risk are increasing and the cybersecurity profession is actively developing models aimed at underpinning techniques for countering such threats. But, there remains a significant capability gap with respect to our ability to protect our AI systems and the business processes they support.

Development is happening in a wider geopolitical and technological context. Current conflicts between nations are serving to energize a period of innovation and capacity-building in cyber-offensive, as well as defensive, techniques. We can expect this to filter through into other domains, such as cybercrime, in the near future. This will mean that we will face greater cyber-threats, with more skills and a growing ecosystem of threat actors.

The global investment in wider technologies and business models, such as the Internet-of-Things and cloud services, will bring about a significant opportunity for developing AI capability – in terms of access to algorithms, models and training datasets, and in AI-as-a-service offerings and solutions that make the technology more accessible and easier to use. This means that those who wish to attack our systems and economies are going to be AI-enabled.

We might currently view as separate the issues of ensuring that decisions recommended by the system are in alignment with our ethics or laws, from that of protecting the AI models from deliberate and covert manipulations by threat actors. But, in time, we can expect attack objectives to be a compromise of the AI system specifically so that it begins to output beyond acceptable and ethical practice, perhaps to extort ransom payments or to release a tainted model or dataset. Such risks are not simply in the realms of our imagination or SciFi channels, they are a direct extension of the kinds of threats we observe daily in cyberspace, in our businesses and throughout our supply chains. Whenever we observe a new technology trend, we can expect harm-potential to arise and so too opportunities for threats to monetize our use of technology.

The need to support effective oversight

The level of threat we face is growing and our dependence on digital technologies and services is creating systemic cyber risk. The aggregation of this remains partially hidden and difficult to predict and quantify. As we utilize AI technologies to inspire and deliver new generations of solutions for some of humankind’s most pressing challenges, there is surely a fiduciary, as well as an ethical, responsibility to ensure that our investments in this technology are not exposed to an unacceptable or unmanageable level of cyber risk. We can expect the cybersecurity profession to deliver ideas, practices and tools, but only if we ensure that there is market demand.

Do we know what we need? At the centre of the solution will be business and we will need leaders to play a role in moving us towards a safe and secure AI-enabled future. An obvious starting position for senior leadership is that of ensuring existing risk controls, those that are invested in, measured and are performing well, can extend to an enterprise model that uses such AI technology. Our insurance providers, investors, customers and regulators will be seeking such a position; we need to possess operational controls that both allow oversight and can be used to defend effectively against motivated threats.

This is non-trivial. There are gaps in existing practice that will be exacerbated by the use of AI, as we do not yet have the specialized cybersecurity solutions available.

• The effectiveness of cybersecurity controls and how to optimize orchestration are not well understood. This means cyber-risk exposure calculations may be inaccurate.

• Senior leadership often lacks digital intuition and the result can be a weak coupling between cybersecurity strategy and the wider business mission.

• Weak scrutiny in the main boardroom means a higher chance of surprise risks being realized, and poor preparation for costly cyber-incidents; similar challenges exist for those charged with oversight of critical national infrastructures or sectors.

DISCOVER

How is the World Economic Forum addressing rising cybersecurity challenges?Show more

The lack of AI-specialized cybersecurity solutions

One example (there are many more) is in the area of threat monitoring and detection. We have never been able to prevent all threats from entering our systems. Even if we could ensure that there were no vulnerable technologies presenting a viable attack surface for external threats (something any security professional would know not to assume), we will always be faced with people with valid access attacking us or selling such access credentials for third parties to use. This means that delivering an ability to detect a compromised system is essential, as otherwise, the reality is that we could be unknowingly using compromised AI to help us make decisions that impact people’s lives and livelihoods, our economies and critical infrastructures.

We do not currently have well-developed threat detection for AI systems. That is an unacceptable situation. How can leaders of nations, global or small businesses be effective in oversight and strategy if they cannot know their systems have lost integrity?

Even once we have the capacity to detect an attack on the AI system, we will need to deploy this alongside all other operational cybersecurity functions. This will require decisions to be taken on how to prioritize concerns being raised by tools and analysts; we simply don’t have the capacity to deal with every possible threat. A key aspect of any mature cyber-defence is the ability to be threat-led, so configuring our limited resources towards those risks determined to be most harmful. Where we are using AI, this will mean we also need to ensure that we can access specialized threat intelligence for AI-enabled threats and actors targeting our AI-enabled businesses. Crucial to success will be the sharing of experiences and threat insights with peers; we need to develop foresight, be able to anticipate threats and thus change our security postures and maintain cyber-resilience.

https://cdn.jwplayer.com/players/9qZm5ek6-ncRE1zO6.html

The importance of leadership

We need to promote organizational cultures that can speak to the concerns being raised around the use of Generative AI. A responsible approach will be open and transparent around its use, support communication with customers and stakeholders, promote care and make efforts to ensure that AI systems are strongly aligned with our values. We may even need to consider backup solutions if we cannot easily wind back the learning should we detect an attack – that might include an ability to switch it off.

Leaders of businesses using AI must insist on operational security capabilities being deployed. Where risks are potentially significant, then they may even need specialized risk assessments and residual cyber-value-at-risk calculations. Commissioning a table-top cyber-risk exercise for the senior leadership that incorporates compromise of AI technology and wider organizational business processes is essential for 2024.

In conclusion, for cybersecure AI systems and businesses, we will require unparalleled levels of dynamism, pace and adaptability. Strong leadership is important, as without it we cannot achieve the organizational pace or the momentum for adaption and resilience. Our ability to pivot and evolve our cyber-resilience depends entirely upon the strength of our core, a core whose DNA is created and evolved by leadership.

The AI Governance Alliance, comprising over 230 members, is committed to advocating for responsible global design, development and deployment of inclusive AI systems. It brings together experts from diverse sectors, uniting to shape the governance and responsible advancement of artificial intelligence. Dive into the cutting edge of AI thought leadership with our blog series, curated by esteemed members of the AI Governance Alliance Steering Committee as we navigate the complex challenges and opportunities in the ever-evolving AI landscape.


Discover more from The European Sting - Critical News & Insights on European Politics, Economy, Foreign Affairs, Business & Technology - europeansting.com

Subscribe to get the latest posts sent to your email.

Interesting reads

© WFP/Jaber Badwan A woman carries food rations distributed by the World Food Programme in Almaghazi, Gaza.

Humanitarian needs in Gaza deepen as aid access remains constrained

This article is published in association with United Nations. Humanitarian needs are continuing to grow again across Gaza, the UN agency assisting Palestine refugees (UNRWA) said on Wednesday, amid mounting pressures on aid delivery and the ongoing conflict in the Middle East.  “Families face ongoing hardship” as access to essential aid remains limited and many continue […]
© WFP/Khadija Dia Food is distributed to displaced families sheltering in a school in Tariq Jdide, Beirut.

Middle East war risks pushing 45 million more people into acute hunger

This article is published in association with United Nations. The Middle East war could cause the worst disruption to lifesaving humanitarian work since COVID, the UN World Food Programme (WFP) warned on Tuesday, as the UN chief again demanded an end to the widening conflict. “The Secretary-General asserts once more that the war in the Middle […]
© World Vision Smoke rises in Beit Mery, close to the Lebanese capital, Beirut, following an airstrike.

Middle East war’s ‘spiral of conflict’ drives mounting civilian toll

This article is published in association with United Nations. The widening war in the Middle East and its growing impact on civilians came under scrutiny at the UN in Geneva on Monday, as independent experts briefing the Human Rights Council warned of escalating violence following the onset of Israeli and US strikes on Iran and counterstrikes […]
© Mousawat A mother and child displaced by the conflict in Lebanon receiving care at a clinic.

Middle East war: Women in Lebanon forced to give birth on roadside

This article is published in association with United Nations. As the UN Secretary-General touched down in Beirut on Friday in solidarity with the people of Lebanon, UN agencies highlighted the dangers for civilians and particularly pregnant women and migrant workers, amid ongoing airstrikes and rocket fire between Hezbollah fighters and Israel.  “There’s 11,600 pregnant women who […]
© WFP/Arete/Ali Yunes Some residents of Beirut who have been displaced by the conflict are now living on the streets of the Lebanese capital.

‘Perfect storm’: Lebanon crisis deepens as civilians bear the brunt

This article is published in association with United Nations. Lebanon is facing a “perfect storm of unpredictable challenges” as conflict, mass displacement and dwindling humanitarian resources converge, the UN’s Resident and Humanitarian Coordinator in Lebanon, Imran Riza, has warned. The current escalation began on 2 March, when outgoing fire by Hezbollah drew a strong retaliation from […]
© WFP/Maxime Le Lijour People living in Gaza have received humanitarian aid from the UN throughout the conflict with Israel.

UN relief chief condemns ‘$1 billion-a-day’ cost of war in Middle East

This article is published in association with United Nations. The UN’s emergency relief chief on Wednesday condemned the “$1 billion-a-day” cost of the war in the Middle East, at a time when humanitarian needs are soaring and aid funding is falling dangerously short. “We’re seeing the consequences spread faster than we can respond”, warned the UN emergency […]
© UNICEF/Azizullah Karimi Afghan returnees from Iran gather at the Islam-Border, near Herat in western Afghanistan (file).

‘Toxic rain’ warning from oil depot strikes amid ongoing Middle East war

This article is published in association with United Nations. Toxic “black rain” linked to strikes on oil depots, mass displacement and continuing disruption to aid supply chains are upending lives across the Middle East and beyond after 10 days of war in the region, UN humanitarians said on Tuesday.  Speaking to reporters in Geneva, UN Human […]
© UNHCR People gather at the Masnaa border point in Lebanon as they wait to cross into Syria.

Nearly 700,000 displaced in Lebanon as Middle East crisis escalates

This article is published in association with United Nations. On day 10 of the war engulfing the Middle East, UN agencies on Monday reported massive displacement across the region, along with surging food and fuel prices that risk increasing hunger and suffering for the most vulnerable. In Lebanon alone, nearly 700,000 people including around 200,000 children […]
UN Photo/Pasqual Gorriz Smoke rises in Beirut, Lebanon, following the outbreak of hostilities across the Middle East.

Lebanon ‘dragged back into turmoil’, UN envoy warns

This article is published in association with United Nations. Lebanon has been “dragged back into a state of turmoil and violence”, the UN’s top envoy in the country warned on Saturday, after the latest round of regional strikes triggered a fast‑escalating crisis along the Blue Line. What had been fragile but real momentum, she said, has […]
UNHCR Smoke rises after an airstrike in Beirut, Lebanon.

MIDDLE EAST LIVE: Strikes continue across Middle East as humanitarian concerns grow

This article is published in association with United Nations. Highlights Production team: Vibhu Mishra with Daniel Johnson in GenevaToday 12:15 μ.μ. UN rights office warns displacement orders in Lebanon affecting hundreds of thousands The UN human rights office has warned that large-scale displacement orders and ongoing airstrikes in Lebanon are worsening the suffering of civilians already affected […]
© UNICEF/Ramzi Haidar Destroyed buildings and debris in the southern suburbs of Beirut, Lebanon, following airstrikes.

MIDDLE EAST LIVE: Further escalation drives uncertainty and suffering

This article is published in association with United Nations. On day six of the war in the Middle East, there’s been no let-up in bombs, drones and rockets targeting Iran, Israel, Lebanon and many Gulf States, while NATO forces reportedly intercepted a missile fired at Türkiye by Iran, a claim denied by Tehran. We’ll bring you […]
UN Photo/Pasqual Gorriz Smoke rises in Beirut, Lebanon, following the outbreak of hostilities across the Middle East.

MIDDLE EAST LIVE: Conflict continues across region amid US, Israeli and Iranian strikes

This article is published in association with United Nations. Violence in the Middle East is continuing into a fifth day, with US and Israeli strikes against Iran and Iranian missile and drone attacks reported across several countries in the region. The escalating confrontation is disrupting airspace, transport and daily life while raising fears of a wider […]
© IAEA/Paolo Contri The Bushehr Nuclear Power Plant in Iran.

Iran crisis: Schoolgirls killed, thousands displaced and aid compromised

This article is published in association with United Nations. On the fourth day of Israeli and United States airstrikes against Iran and amid growing violence and instability in the Middle East, the UN urgently called for protection of civilians and warned of growing displacement and humanitarian needs. UN human rights office spokesperson Ravina Shamdasani also recalled […]
© Unsplash/Kamran Gholami Tehran, the capital of Iran. (file photo)

MIDDLE EAST LIVE: Strikes continue from US, Israel and Iran as UN urges restraint

This article is published in association with United Nations. Violent escalation in the Middle East has entered a third day as coordinated US and Israeli strikes against Iran aimed at regime change continue to cause loss of life and damage across the region, prompting Iranian missile and drone counter-strikes hitting targets in multiple countries. Explosions, airspace […]
Iran attacks

Deadly bombing of Iran primary school ‘a grave violation of humanitarian law’: UNESCO

This article is published in association with United Nations. The UN education agency, UNESCO, says that the bombing of a primary school during the US and Israeli military attacks on Iran on Saturday constitutes a grave violation of humanitarian law. The missiles reportedly destroyed a girl’s primary school in Minab, southern Iran, killing around 150 and […]
© UNRCO Iran Tehran, the capital of Iran.

Attacks on Iran and retaliatory strikes ‘undermine international peace and security’

This article is published in association with United Nations. UN Secretary-General António Guterres and the heads of UN agencies have condemned Saturday’s joint Israeli and US attacks on Iran and the Iranian retaliatory strikes on Israel and the Gulf Regions. The attack on Iran reportedly targeted military sites as well as the leadership of the Iranian […]
© WFP/Maxime Le Lijour A woman holds a child as a storm approaches Khan Younis in Gaza.

Palestine: UN rights chief highlights suffering, atrocity crimes ‘that remain unpunished

This article is published in association with United Nations. The UN rights chief Volker Türk on Thursday highlighted the “human-made disaster” across the Occupied Palestinian Territory stemming from Israel’s disregard for human rights norms and serious violations also committed by Hamas and other Palestinian armed groups. Citing a new report from his office (OHCHR) covering the […]
Ángela Soria Pitarch was born on March 28, 2003. She is currently a fifth-year medical student at the University of Valencia.

Not the Future, the Present: Young Voices Shaping Global Health in 2026

This article was exclusively written for The European Sting by Ms. Ángela Soria Pitarch was born on March 28, 2003. She is currently a fifth-year medical student at the University of Valencia. She is affiliated with the International Federation of Medical Students Associations (IFMSA), cordial partner of The Sting. The opinions expressed in this piece belong strictly to […]
© UNOCHA Many rural areas of Ukraine have been blasted by shelling and drone strikes. The country is also one of the most mined in the world, top UN aid officials warn.

Ukraine wakes to more violence as Russia’s invasion enters fifth year

This article is published in association with United Nations. The full-scale invasion of Ukraine by Russian troops on 24 February 2022 shattered the peaceful aspirations of an entire continent, but war must never be the new normal, UN General Assembly President Annalena Baerbock said on Tuesday. “Four years ago, people in Europe woke up in another […]

Why don't you drop your comment here?

Go back up

Discover more from The European Sting - Critical News & Insights on European Politics, Economy, Foreign Affairs, Business & Technology - europeansting.com

Subscribe now to keep reading and get access to the full archive.

Continue reading

Discover more from The European Sting - Critical News & Insights on European Politics, Economy, Foreign Affairs, Business & Technology - europeansting.com

Subscribe now to keep reading and get access to the full archive.

Continue reading

The European Sting – Critical News & Insights on European Politics, Economy, Foreign Affairs, Business & Technology – europeansting.com