Driven by the generative AI storm, the need to build a more secure artificial intelligence (AI) future has become increasingly important. To address this, Google unveiled its Secure AI Framework designed to ensure that AI models are secure-by-default.
The Secure AI Framework (SAIF) is a conceptual framework for secure AI systems that aims to help mitigate AI-related risks, including theft of the model, data poisoning of the training data, injecting malicious inputs through prompt injection and extraction of confidential information in the training data, according to Google.
“A framework across the public and private sectors is essential for making sure that responsible actors safeguard the technology that supports AI advancements so that when AI models are implemented, they’re secure-by-default,” Google Cloud VP and CISO Phil Venables, and Royal Hansen, VP of privacy, safety and security engineering at Google, wrote in a blog post.
The SAIF has six core elements:
1. Expand strong security foundations to the AI ecosystemGoogle recommends leveraging secure-by-default infrastructure protections and expertise built over the last two decades and starting to scale and adopt those security foundations in the context of AI and the evolving threat landscape.
2. Extend detection and response to bring AI into an organization’s threat universeSecurity teams should collaborate with trust and safety, threat intelligence and counter-abuse teams to monitor inputs and outputs of generative AI systems to detect anomalies and use threat intelligence to anticipate attacks.
3. Automate defenses to keep pace with existing and new threatsAs adversaries may use AI to scale their impact, it is essential for organizations to also use AI and its emerging capabilities to stay nimble and cost-effective in protection efforts.
4. Harmonize platform-level controls to ensure consistent security across the organizationConsistency across control frameworks can support AI risk mitigation and scale protections across different platforms and tools for all AI applications.
5. Adapt controls to adjust mitigations and create faster feedback loops for AI deploymentOrganizations should constantly test AI implementations through continuous learning based on incidents and user feedback to ensure detection and protection capabilities.
6. Contextualize AI system risks in surrounding business processesConduct assessment of the end-to-end business risk including data lineage, validation and operational behavior monitoring for certain types of applications and construct automated checks to validate AI performance.
Industry experts welcome Google’s SAIF initiativeGoogle claims it's helping to develop the NIST AI Risk Management Framework and ISO/IEC 42001 AI Management System Standard and Secure AI Framework elements consistent with those two institutes' existing security standards. And the vendor plans to publish several open-source tools to help put SAIF elements into practice for AI security.
JupiterOne CISO Sounil Yu agrees that "the SAIF is a great start, anchoring on several tenets that are found in the NIST Cybersecurity Framework and ISO 27001.
“AI safety is an extremely important principle to consider at the earliest stages of designing and developing AI systems because of potential catastrophic and irreversible outcomes,” Yu said in a statement. “As AI systems grow more competent, they may perform actions not aligned with human values.”
SlashNext CEO Patrick Harr added, "the most important takeaway is the need for a thorough security protocol when using AI-generated programs," and he expects to see more security tools and recommendations to mitigate AI-related risks.
HiddenLayer cofounder and CEO Christopher "Tito" Sestito echoed Google's announcement comes at a critical time and serves as a strong indication of the global responsibility to secure AI at its rapid pace of adoption.
Sestito noted the automated detection and response element in Google’s SAIF aligns with a recent Forrester report — Zero Trust for AI, which showed more than 85% of respondents listed "protection from zero-day and cyberattacks" as their top priority in securing their AI systems.
Comments