The No. 1 question Amazon Web Services (AWS) CISO Chris Betz recently received from customers is, “How do I do security in a generative artificial intelligence (genAI) world?” Betz explained that the provider's approach remains grounded in its core cloud security principles, while leveraging genAI to strengthen cybersecurity measures and building a platform for customers to use the technology securely.
Regarding concerns about genAI security, customers approach Betz with two main types of questions: What is AWS doing to secure genAI? And as a customer wanting to build genAI models, what should they be thinking about for security based on the experiences of other AWS users?
- For the first question, the conversation often starts with data security. Betz said he emphasizes the importance of securely managing and storing data. This includes ensuring data availability and efficiency for genAI model training. In addition, fundamental data security strategies apply to genAI as with other domains, he said.
- Then, the conversation generally extends to interacting with the genAI models, including the secure handling of prompts and responses. Betz highlights the need for organizations to protect sensitive customer data that may be included in prompts.
- The third place their conversation goes is recognition of the genAI models. “Models are code,” Betz said. “And that means that models operate like any code; you need to be careful about where you get the model from.” He added that users should treat genAI models with the same scrutiny as any software code — taking into account supply chain risks and potential vulnerabilities — and make sure their infrastructure is set up to manage these issues properly.
- Lastly, Betz said his discussions with customers tend to wrap up with how important the accuracy of outputs by genAI models are. He recommends organizations implement filtering and guardrails on model inputs and outputs, as well as security mechanisms to ensure these outputs are accurate, reliable and safe.
Betz emphasizes that recent AI developments have not altered the core principles of the public cloud giant’s shared responsibility model. AWS continues to take its responsibility of protecting the infrastructure that runs all of the services offered in its public cloud seriously.
“There are pieces of the infrastructure that I control, and customers need to trust me to do well in. And there are pieces of the infrastructure that the customer controls and I need to equip them to be operating in as secure a way as possible in that space,” Betz said.
The hyperscaler has built a platform with multiple layers of services for genAI applications, models and model training environments. Services such as Amazon Bedrock — a managed service for building genAI applications with foundation models, CodeWhisperer — an AI-powered productivity tool for the integrated development environment (IDE) and command line, and Amazon Q — a genAI-powered assistant.
“It's still our job to make sure that the platform underneath is secure and stable,” Betz said. “We're still responsible for providing a trustworthy platform. And we're still responsible for giving customers tools that allow them to operate securely, all based on the premise that their data is theirs.”
Securing the platform for genAI useAs a public cloud infrastructure and platform provider, AWS offers a consistent set of protections around customers’ data, environments and tools for genAI or other emerging technologies, Betz said.
He outlined some of AWS’s key security factors and services for genAI, including identification and authentication management, data protection to ensure data remains secure and correctly located and stored, data resilience and management, and account logging and auditing.
In addition, AWS uses existing well-defined models such as Amazon Simple Storage Service (Amazon S3) that already have robust security controls built in.
Image: AWS CISO Chris Betz. Credit: AWS.
Comments