Home Security Invisible, autonomous and hackable: The AI agent dilemma no one saw coming

Invisible, autonomous and hackable: The AI agent dilemma no one saw coming

by
0 comment
Invisible, autonomous and hackable: The AI agent dilemma no one saw coming

This text is a part of VentureBeat’s particular situation, “The cyber resilience playbook: Navigating the brand new period of threats.” Learn extra from this particular situation right here.

Generative AI poses fascinating safety questions, and as enterprises transfer into the agentic world, these issues of safety improve. 

When AI brokers enter workflows, they need to be capable to entry delicate knowledge and paperwork to do their job — making them a big danger for a lot of security-minded enterprises.

“The rising use of multi-agent programs will introduce new assault vectors and vulnerabilities that may very well be exploited in the event that they aren’t secured correctly from the beginning,” stated Nicole Carignan, VP of strategic cyber AI at Darktrace. “However the impacts and harms of these vulnerabilities may very well be even greater due to the growing quantity of connection factors and interfaces that multi-agent programs have.”

Why AI brokers pose such a excessive safety danger

AI brokers — or autonomous AI that executes actions on customers’ behalf — have change into extraordinarily standard in simply the previous few months. Ideally, they are often plugged into tedious workflows and might carry out any job, from one thing so simple as discovering info based mostly on inside paperwork to creating suggestions for human workers to take.

See also  OpenAI reportedly plans to launch an AI agent early next year

However they current an fascinating drawback for enterprise safety professionals: They need to acquire entry to knowledge that makes them efficient, with out by chance opening or sending non-public info to others. With brokers doing extra of the duties human workers used to do, the query of accuracy and accountability comes into play, probably changing into a headache for safety and compliance groups. 

Chris Betz, CISO of AWS, informed VentureBeat that retrieval-augmented technology (RAG) and agentic use instances “are an interesting and fascinating angle” in safety. 

“Organizations are going to want to consider what default sharing of their group appears like, as a result of an agent will discover by search something that can assist its mission,” stated Betz. “And if you happen to overshare paperwork, it is advisable to be excited about the default sharing coverage in your group.”

Safety professionals should then ask if brokers ought to be thought of digital workers or software program. How a lot entry ought to brokers have? How ought to they be recognized?

AI agent vulnerabilities

Gen AI has made many enterprises extra conscious of potential vulnerabilities, however brokers might open them to much more points.

“Assaults that we see at present impacting single-agent programs, resembling knowledge poisoning, immediate injection or social engineering to affect agent conduct, might all be vulnerabilities inside a multi-agent system,” stated Carignan. 

Enterprises should take note of what brokers are capable of entry to make sure knowledge safety stays robust. 

Betz identified that many safety points surrounding human worker entry can lengthen to brokers. Due to this fact, it “comes down to creating positive that folks have entry to the precise issues and solely the precise issues.” He added that in the case of agentic workflows with a number of steps, “every a kind of phases is a chance” for hackers.

See also  Why MFA alone won't protect you in the age of adversarial AI

Give brokers an id

One reply may very well be issuing particular entry identities to brokers. 

A world the place fashions motive about issues over the course of days is “a world the place we should be considering extra round recording the id of the agent in addition to the id of the human answerable for that agent request all over the place in our group,” stated Jason Clinton, CISO of mannequin supplier Anthropic

Figuring out human workers is one thing enterprises have been doing for a really very long time. They’ve particular jobs; they’ve an electronic mail handle they use to signal into accounts and be tracked by IT directors; they’ve bodily laptops with accounts that may be locked. They get particular person permission to entry some knowledge.

A variation of this type of worker entry and identification may very well be deployed to brokers. 

Each Betz and Clinton consider this course of can immediate enterprise leaders to rethink how they supply info entry to customers. It might even lead organizations to overtake their workflows. 

“Utilizing an agentic workflow truly provides you a chance to certain the use instances for every step alongside the best way to the info it wants as a part of the RAG, however solely the info it wants,” stated Betz. 

He added that agentic workflows “will help handle a few of these issues about oversharing,” as a result of firms should think about what knowledge is being accessed to finish actions. Clinton added that in a workflow designed round a particular set of operations, “there’s no motive why the 1st step must have entry to the identical knowledge that step seven wants.”

See also  Nvidia just dropped a new AI model that crushes OpenAI’s GPT-4—no big launch, just big results

The old school audit isn’t sufficient

Enterprises also can search for agentic platforms that enable them to peek inside how brokers work. For instance, Don Schuerman, CTO of workflow automation supplier Pega, stated his firm helps guarantee agentic safety by telling the consumer what the agent is doing. 

“Our platform is already getting used to audit the work people are doing, so we will additionally audit each step an agent is doing,” Schuerman informed VentureBeat. 

Pega’s latest product, AgentX, permits human customers to toggle to a display screen outlining the steps an agent undertakes. Customers can see the place alongside the workflow timeline the agent is and get a readout of its particular actions. 

Audits, timelines and identification are usually not excellent options to the safety points offered by AI brokers. However as enterprises discover brokers’ potential and start to deploy them, extra focused solutions might come up as AI experimentation continues. 

Source link

You may also like

Leave a Comment

cbn (2)

Discover the latest in tech and cyber news. Stay informed on cybersecurity threats, innovations, and industry trends with our comprehensive coverage. Dive into the ever-evolving world of technology with us.

© 2024 cyberbeatnews.com – All Rights Reserved.