Artificial Intelligence & Cybersecurity: Math Not Magic


Wayne Chung
CTO
FBI

Introduction

The field of cybersecurity has slowly progressed from an art to a science. It has been a long and complicated journey that is still punctuated by misunderstandings and lack of rigor. 

The field of artificial intelligence, however, has further transformed from a science to something more akin to magic. The combination of the two has led to a complex, nuanced, and buzzword-laden field that may leave many of us insecure and overly reliant on tools we fundamentally don’t understand. 

This talk will cover some of the realities of AI systems in cybersecurity and how they can be leveraged as a force multiplier for the time-and-resource-limited cyber security analyst.

Watch Wayne Chung’s full presentation here

What you need to do right off the bat to make AI effective for your business

  • Make sure your data is useful. AI is all about data, and it’s hard to get utility out of your data. You need to do a lot of work. 
  • Make sure you are working with accurate labeling. Data is not useful unless it’s labeled for supervised systems. It needs to be labeled tag retrievable. 
  • Know who is giving you your data. A lot of big data companies use their customers for data. However, if you’re not one of these big players, you have to pay someone for data. Most AI is built on people. Do we know who is building our data sets, and should we care? How are they manipulating the data that it may change the way our models react? 

Is AI math or magic? 

AI is math, not magic. It’s about identifying features and performing separations. 

Problem: we don’t know when the model fails. We don’t yet have an underlying understanding of these deep learning systems to know when they are weak, when they’re not weak, and when their failure modes are fundamentally different from the failure modes we understand. 

Why it’s important to listen to your experts:

AI has become really good at finding what we’re asking it to find. 

Problem: the environment is not stationary. The subject we were once telling AI to find may no longer be relevant as the situation changes. We need a way of differentiating the features we care about. 

There is a danger in AI experts spending time and money in building programs that may already exist. If you just ask an expert, you could have avoided the wasted time and money. 

  • Work with your experts from the very start. When you are working with unsupervised learning, you are trying to figure out what is normal for your network. If you have a small office, eventually, you can figure out what is supposed to be on your network (usually). If you have a larger office or multiple offices, you may never be able to figure out every single thing that needs to be on your network. Those larger networks are so complex that it’s often hard to figure out what’s going on. 
  • Bottom line: experts can tell us what is normal and what isn’t normal in what they’re seeing. 

The Internet is really weird! 

Like many things on the Internet, remember that just because it’s weird and an anomaly doesn’t mean that it’s necessarily bad. 

  • Work with your analysts to make sure they know what it is that they’re looking for. 
  • Don’t just work with AI experts but also your subject matter experts. Your AI experts may just ignore things or turn them off, because the AI is not finding anything they care about. 

AI and Cybersecurity

How do we validate what we are doing given that we have people trying to sneak in and manipulate our networks? There are people who are intentionally trying to do bad things. How will these attacks affect our data? When do we even realize that it’s happening?

In the first quarter of 2019 alone, there were over $10 million in losses reported by the three major banks. This was due to a business email compromise. 

  • Keep in mind that your business partners and your bank accounts are not constantly changing. If they are, it’s a red flag. Email should never move money. This would not even technically be considered fraud, because you personally told the banks to move money to a certain place. They did what you told them to do. That money is gone. You are accountable for that loss. 

How can AI actually be used with cybersecurity in mind? 

  • Focus on specific narrow tasks. 
  • Use data that will actually make it useful. 
  • Use both domain and AI expertise, not just one or the other. Build a team. 
  • Weigh the consequences. Test with real-world data and real-world conditions, but never with real-world consequences. 

Bottom line: AI does what you ask it to do, so be prepared for that. 

If you think you’ve been a victim of a crime, please contact your local FBI field office. If you don’t have a relationship with them now, reach out — agents love having a working relationship.


Tags   •   Cybersecurity

Comments

Leave a Reply

Your email address will not be published. Required fields are marked *

blog

Appreciate the recommendation. Let me try it out.

ring planner wallet insert

There may be definately a whole lot to check out this issue. I adore all the points you made.

JameAMelusky

I'm really impressed together with your writing skills and in addition together with the layout on your own weblog. Is it a paid theme or do you modify it yourself? In either case continue the excellent quality writing, it's rare to discover a great blog like this one today.

ExieJGails

Hello I am so grateful I found your website, I really found you by mistake, while I was searching on Google for something else, Anyhow I am here now and would just like to say thanks for a remarkable post and a all round entertaining blog (I also love the theme/design), I don’t have time to browse it all at the minute but I have bookmarked it and also added your RSS feeds, so when I have time I will be back to read a lot more, Please do keep up the fantastic work.

RyanGUrion

Hello there, I found your blog through Google while in search of a similar subject, your website got here up, it seems good. I have got bookmarked it in my google bookmarks.

Related Posts

Recent Posts

How AI is Revolutionizing Education -   Artificial intelligence has become increasingly relevant in a number of major industries. We read a lot about how it’s…
Three Amazing Ways AI is Revolutionizing Healthcare - It may not seem like it was too long ago when the idea of artificial intelligence playing a major role…
How 5G is Going to Impact AI in Automation Within Telecom - During this webinar, an industry expert discussed how an automation project comes to life from the initial business problem through…
How Automation Projects Come to Life in Telecom - During this webinar, an industry expert discussed how an automation project comes to life from the initial business problem through…
The Future of AI in Marketing - During this webinar, industry experts discussed where AI in marketing was heading in the future. We’ve included a short transcription…
How AI Has Changed Marketing - During this webinar, industry experts discussed how AI has changed the marketing industry. We’ve included a short transcription of the…
Key Takeaways From Ai4 2020 - Artificial Intelligence Creates the Demand of Innovation, Autonomy, and Personalization Amidst a Crisis There is a seemingly quiet, yet enormous…
Computer Vision Versus Other ML Projects - During this webinar, industry experts discussed computer vision projects versus other machine learning projects within an enterprise setting. We’ve included…
Computer Vision in the Enterprise - During this webinar, industry experts discussed if computer vision computer is commonplace within enterprises that have machine learning models in…
How AI is Enabling Banks to Provide a Better User Experience - During this webinar, industry experts discussed how AI is enabling banks to provide a better user experience for having both…

Popular Posts

Does Healthcare AI Meet Basic Ethics Principles? - Ingrid Vasiliu-Feltes Chief Quality and Innovation Officer MEDNAX, Health Solutions Partner Over the past decade we have noticed an exponential…
Machine Learning and Artificial Intelligence in Banking - Artit "Art" Wangperawong Distinguished Engineer US Bank Introduction Every company’s AI journey is different. We’re all trying to figure out…
Machine Learning for Pricing and Inventory Optimization @ Macy’s - Jolene Mork Senior Data Scientist Macy's Iain Stitt Data Scientist Macy's Bhagyesh Phanse VP, Data Science Macy's Overview In this…
Artificial Intelligence & Cybersecurity: Math Not Magic - Wayne Chung CTO FBI Introduction The field of cybersecurity has slowly progressed from an art to a science. It has…
AI/ML in Investment and Risk Management: Recent Applications, Use Cases, and Implementation Challenges - Arvind Rajan Managing Director - Head of Global & Macro PGIM Fixed Income Introduction Investing is a completely different ballgame…
Top AI Conferences - Interested in learning the latest in AI this year? We’ve compiled a list of the top artificial intelligence conferences in…
Machine Learning in Production: From Research to the Customer - Ameen Kazerouni Lead Data Scientist Zappos Overview In this presentation Ameen Kazerouni, the Lead Data Scientist at Zappos, walks through…
How COVID-19 is Impacting the State of AI in Banking - On this panel, industry experts (listed above) discussed The State of AI in Banking and how COVID-19 is affecting it.…
“Ask Me Anything” with Zappos’s Head of AI/ML Research & Platforms, Ameen Kazerouni - Ameen Kazerouni Head of AI/ML Research & Platforms Zappos Family of Companies Ai4 recently hosted an "Ask Me Anything" session…
The Autonomous Pharmacy: Applying AI and ML to Medication Management Across the Care Continuum - Ken Perez VP of Healthcare Policy Omnicell, Inc. Ken applies artificial intelligence (AI) and machine learning (ML) solutions to medication…