We need to be doing defence at computer speed, says Google Threat Intelligence Group’s Senior Director
Account subscription benefits alongside Premium Stories, Editorials, Opinions and more. Unlock these with Subscription
Shane Huntley, Google Threat Intelligence Group’s Senior Director | Photo Credit: Special Arrangement
For several weeks now, technologists in the U.S. have been drumming up support for more open-weight AI model launches in order to keep ahead of China’s AI, even as they weigh up the security risks of models that users can modify and run independently.
While regulatory debates strongly differentiate between closed and open-weight models, Shane Huntley, CTO and Senior Director at Google’s Threat Intelligence Group, challenged this black-and-white approach when thinking about AI cyber-attacks and cyber-defence.
In an interaction with The Hindu , Mr. Huntley said that he had been tracking with great interest the news stories about AI models going rogue, observing that every month saw something happening in AI that would have “felt like science fiction a month before.”
“So, I certainly think that the models and what we saw here with these attacks are a real threat. It just shows how much investment in AI safety is important, in alignment, in making sure we actually have close control,” he explained.
Mr. Huntley believed that the AI ecosystem would support both open and closed models for a long time, similar to how tech users today can choose between open-source and closed-source software.
“I think the open models do show us that these capabilities are going to be out there; this is not a technology that we can fully constrain. They can’t just control how these hackers use AI, via controlling the environment,” Mr. Huntley said.
He added that Google ensured its models were used on the defence side first, and that the company collaborated with good faith actors to address their vulnerabilities before a broader model release. Noting that Google released both closed models (like Gemini) as well as open-weight models (like Gemma), Mr. Huntley said it was not a “black-and-white situation.”
The Google executive observed that when an AI cyber-attack takes place, pinpointing which model version or agent or hardware or open/closed model provider was involved, can be difficult at times. This is increasingly the case as the hardware required to run sophisticated models can now be bought by everyday users at their local stores.
“If we see somebody doing an automated attack, can we really tell if it’s running in a data centre somewhere, or if it’s running in somebody’s local machine, or somewhere else? There’s just so many models out there. So, it’s such an explosion of capability here. And we’re certainly seeing very imaginative use,” Mr. Huntley remarked.
Regarding some agentic attacks, Mr. Huntley said there were incidents where people connected models to open source attacking tools and then automated their attacks in order to go after different victims.
In other words, attackers are using a range of tools — both open and closed — to carry out cyber crimes.
“And I think one of the other things we really see is the speed, right? The scale.
5News aggregated this summary from the outlet’s public feed. The full article, with all the context, is on www.thehindu.com — the content belongs to The Hindu - Sci-Tech.