July 2024

SGV thought leadership on pressing issues faced by chief executives in today’s economic landscape. Articles are published every Monday in the Economy section of the BusinessWorld newspaper.
08 July 2024 Rajiv Kakar

Key GenAI cybersecurity challenges and risk mitigation strategies

Generative artificial intelligence (GenAI) has the capacity to understand, learn, adapt, and implement knowledge across a broad range of tasks at a level equal to or beyond human capability. Unlike Narrow AI, which is designed to perform a specific task such as voice recognition or recommendation algorithms, GenAI can apply intelligence to any problem, and be able to perform any intellectual task that a human being can do.While it holds extraordinary promise for the future, GenAI comes shrouded in various concerns, extending from ethical dilemmas to security susceptibilities. This article will explore some of the key challenges of GenAI and risk mitigation strategies from a cybersecurity perspective.Key challenges of GenAI A persistent issue of AI is the lack of transparency, frequently referred to as the black box problem. It’s difficult to understand how complex AI models make decisions, and this can create a security risk by allowing biased or malicious behavior to go unchecked.Businesses are rapidly exploring GenAI solutions with little forethought on the security implications on the rest of the IT estate. There is currently no limit for the complexity of attack surfaces of AI systems or other security abuses enabled by AI systems. In addition, AI models heavily rely on third-party technologies, where the large language models (LLMs) like ChatGPT are outside the control of an enterprise. Consequently, the learning parameters where AI systems may be trained for decision-making outside an organization’s security controls or trained in one domain and then “fine-tuned” for another raises concerns about intended and actual usage.Datasets used to train AI systems may become detached from their original and intended context, or may become stale or outdated relative to deployment. This introduces the problem of decisions made on incorrect data. Moreover, changes during training of models may fundamentally alter AI system performance and outcomes.LLMs typically capture more information than they process, and considering the privacy policy of ChatGPT, the platform may regularly collect user data such as IP address, browser info and browsing activity. These may be shared with third parties, competitors, and regulators. The use of pre-trained models that can advance research and improve performance can also increase levels of statistical uncertainty and cause issues with bias management, scientific validity, and reproducibility.On top of the computational costs for developing AI systems and their impact on the environment and planet, it is very difficult to predict failure modes for the emergent properties of large-scale pre-trained models. AI systems may require more frequent maintenance and triggers for conducting corrective maintenance. Additionally, it is challenging to perform regular AI-based software testing, or determine what to test, since AI systems are not subject to the same controls as traditional code development.“Artificial stupidity,” the term used to describe situations where AI takes decisions that may seem illogical to humans due to its inadequate understanding of the real-world context, presents another challenge. Talks of AI singularity, a hypothetical scenario where AI outstrips human intelligence, have also started to gather momentum. Critics argue that a super-intelligent AI poses a real existential risk, as it might spin out of human control. The dehumanizing effects of GenAI are another cause for concern. Over-reliance on AI risks devaluing human skills and minimizing human interactions. Moreover, the widespread application of GenAI may give rise to economic disparity, as the benefits of AI may not distribute evenly across society. Finally, the misuse of GenAI, particularly for harmful purposes like illegal surveillance, spreading propaganda, or weaponization, cannot be overstated.The already dense and complex AI landscape is further complicated by substantial hype and a multitude of diverse solutions. The resulting application environment is scattered with multiple third-party technology solution components which require thorough vetting in enterprise contexts. Types of GenAI attacksThere are various types of GenAI attacks manifesting across enterprises. Adversarial attacks involve manipulating an AI model's input data to make the model behave in a way that the attacker desires, without triggering an alarm. For example, an attacker could manipulate a facial recognition system to misidentify an individual, allowing unauthorized access. A data poisoning attack involves maliciously manipulating the data used to train AI models. By introducing false or misleading data into the training dataset, attackers can compromise the accuracy and reliability of AI systems. This can lead to biased predictions or compromised decision-making. On the other hand, a model theft or model inversion attack may attempt to steal and/or reverse-engineer AI models to obtain sensitive information. In a transfer learning attack, an attacker manipulates an AI model by transferring knowledge gained from one domain to another, resulting in the AI system producing incorrect or harmful outcomes when applied to new tasks. In input manipulation, interacting with a chatbot or an AI-driven system can lead to incorrect or harmful responses simply by changing words or asking tricky questions. For instance, a medical chatbot might misinterpret a health query, potentially providing inaccurate medical advice.AI can also be used by malicious actors to automate and enhance their cyberattacks. This includes using AI to perform more sophisticated phishing attacks, automate the discovery of vulnerabilities, or conduct faster, more effective brute-force attacks.GenAI security risk managementTo mitigate attack vectors, organizations must establish comprehensive regulations and standards that can guide the responsible use and development of GenAI. A GenAI Risk and Control framework can be very helpful in highlighting areas of vulnerability and risk mitigation in some of the following areas:  Threat recognition. Identify possible threats GenAI might enable, such as autopilot system hacking, data privacy threats, decision-making distortion, or manipulation.Vulnerability Assessment. Evaluate weak spots in the system that might be exploited due to GenAI characteristics.Risk Impact Analysis. Look into potential implications if any threats were actualized (financial implications, impact on company reputation, etc.)Mitigation Strategy Development. Develop strategies to mitigate these risks, whether that means strengthening your network security system, creating backup systems, securing data privacy with improved encryption, or continuously auditing & updating the AI’s programming against potential manipulation.Contingency Planning. Develop a plan for responding to any breaches or issues that occur, despite mitigation efforts. Include steps to fix the issue, mitigate the damage, and prevent future occurrences.Constant Monitoring & Updating. GenAI systems should be regularly monitored and updated to patch vulnerabilities and keep up with the evolving threat landscape.Training & Awareness. Ensure that all users of GenAI systems are properly trained on security best practices and are aware of the potential threats.External Cooperation. Cooperate with other firms and institutions to share threat intelligence and promote a collective defense strategy.Regulation Compliance. Ensure compliance with all applicable laws and regulations surrounding data security and AI, such as general data protection regulation (GDPR).Incident Response Plan. Prepare a clear and concise plan to follow when a breach occurs, which includes reporting breaches, managing and controlling the situation.Organizations must consider upgrading cloud security and moving towards zero trust principles, whereby every access request is authenticated, authorized and validated every time. Antivirus systems should be upgraded from the current norm of using a pre-programmed list of known attack vectors (signature based) to systems that can observe unusual patterns and alert on deviations (anomaly based). Embracing GenAI monitoring by introducing the appropriate tools allows organizations to monitor AI prompts and see that they do not deviate from original scenarios.Review and strengthen security around a GenAI application stack emphasizing on integration points between systems (API’s) and identify AI systems and assets by drawing up a plan of usage. Organizations can assign a dedicated team to test AI models at base and application level, as well as introduce moderation and control on user developed applications, tools and products. Any experimental or uncontrolled work on GenAI within the enterprise must be monitored.Applying these strategies can minimize the risks associated with GenAI and help efficiently manage cybersecurity.Navigating AI pitfalls by mitigating risksWhile the potential of GenAI is undeniable, a cautious, forward-thinking approach is crucial to navigating its potential pitfalls. It is imperative to establish comprehensive risk mitigation, standards, and frameworks that can guide the responsible use and development of GenAI. Rajiv Kakar is a Technology Consulting Principal of SGV & Co.This article is for general information only and is not a substitute for professional advice where the facts and circumstances warrant. The views and opinions expressed above are those of the author and do not necessarily represent the views of SGV & Co.

Read More
01 July 2024 Ryan Gilbert K. Chua

Realizing potential with GenAI

The significance of managing generative artificial intelligence (GenAI) initiatives is underscored by a white paper from Pactera Technologies, a leading global technology company, which indicated that a substantial 85% of these projects fall short. Forbes corroborates that the majority of GenAI projects do not meet expectations, underscoring a problematic trend in the field. GenAI projects possess characteristics that differentiate them from standard software development undertakings. Consequently, the strategies employed in overseeing and realizing the potential of GenAI projects demand a tailored approach distinct from conventional software project management. To address this issue and enhance AI project management methodologies, this article will discuss the following fundamental principles designed to refine the management of GenAI-related projects.Establishing clear business objectives and the importance of planningTo fully harness the potential of GenAI, it's essential to establish specific, measurable, achievable, relevant, and time-bound (SMART) goals for the GenAI solution to achieve. This crucial step involves a deep understanding of the underlying business problem or challenge that the GenAI solution intends to address. It is also vital to consider whether GenAI is the most suitable solution, ensuring that the technology is not simply being used for its own sake.Identify and rationalize potential use cases for GenAI that are in sync with core business objectives. This involves a process of prioritization - pinpointing which GenAI applications can deliver the highest value in alignment with the strategic direction of the organization. By focusing on areas where GenAI can make a significant impact, businesses can channel their resources more efficiently and create a tailored approach that maximizes its benefits. For instance, a common application of GenAI is in knowledge management, which could provide value across the enterprise.Understanding the project life cycle is another fundamental aspect of managing and executing a GenAI project successfully. Establish the stages the project will go through, including a comprehensive methodology that covers various phases such as planning, developing, testing, deploying, and monitoring the GenAI solution. While each stage of the project is important, an emphasis on key differences in developing and monitoring traditional and GenAI solutions is important. For example, in developing GenAI solutions, model “training” directly impacts the performance of the solution in production. Likewise, monitoring performance for its accuracy and precision would be continuous throughout the use of the solution.Selecting the appropriate tools and methodology is equally critical. Whether in terms of data processing software, programming languages, and platforms for deployment, these must be chosen with the aim of enhancing the productivity and effectiveness of the GenAI solution.Understanding dependencies and prerequisites GenAI solutions depend on a process often referred to as "learning," which involves feeding them a substantial volume of historical business data. This data acts as the foundation upon which the GenAI model is adjusted and refined, making it crucial that this information is of high quality. The principle of "garbage in, garbage out" is applicable here, as any shortcomings in the data can lead to flawed results. As the system continues to process new data, its effectiveness is influenced by the accuracy, completeness, and overall integrity of the information it receives.Another key aspect is the existing technological infrastructure and the broader system of the company. The current architecture and its capacities must be evaluated to determine how they might integrate with or support the effective deployment of the GenAI system. This includes considering the capability of current systems to communicate with the GenAI solutions and manage the additional workload. Scalability also cannot be overlooked. While GenAI can be a powerful business enabler, it requires the proper infrastructure to unlock its full potential. For example, GenAI solutions require significant computational power to function properly, thus, a powerful hardware component will accelerate “learning” of complex algorithms. The implications of GenAI on existing business processes are profound. The adoption of GenAI systems can lead to a complete overhaul of current processes, possibly making some obsolete. This makes it essential to perform a meticulous gap analysis to understand the differences between current state and future state business processes. This helps businesses ensure they can capitalize on the advantages GenAI offers while mitigating any operational disruptions.Cross-functional collaborationGenAI initiatives will require cross-functional collaboration. A diverse team composition is necessary due to GenAI projects intersecting multiple domains, requiring a holistic understanding of each area to create solutions that are not only technically advanced but also practical and relevant to the business. For example, a GenAI solution includes business process, application, infrastructure, and data components. To be able to design the solution, it will require the business unit to define the business problem, legal unit to provide compliance requirements, IT unit to provide data, infrastructure and other system requirements, HR unit to manage change, and senior leaders to drive its adoption.   Adequate training will be crucial in ensuring that each team member can contribute effectively and understand the complexities of the tasks at hand. A data scientist, for example, must understand not just the intricacies of algorithms and model-building but also the business problems the technology is meant to solve. It is also imperative to involve cross-functional teams from the earliest stages. Collaboration should be established from the beginning, mixing technical expertise with business insights and ethical considerations. This allows every aspect of the project to be scrutinized from multiple perspectives, fostering an environment where technical feasibility, business viability, and ethical implications are all weighed and balanced. This blended approach ensures that the solutions developed are realistic, beneficial for the business, and designed with a consideration of their impact on stakeholders and society at large.Change managementOne common issue in implementing a GenAI solution is resistance. While people may be hesitant to adopt new technologies in favor of established routines, it's essential for companies to anticipate this resistance and prepare with strategies to address concerns and ease the transition for everyone involved.To facilitate adaptation, the company should provide substantial training and dedicated support. Instructional programs designed to enhance understanding of the new GenAI system can empower employees. Additionally, a hypercare support system, which offers intensive post-implementation assistance, ensures that immediate help is available for any issues or questions that may arise during the initial stages of using the new technology.Stakeholder management is also a critical component in ensuring a smooth transition. Clear and transparent communication regarding sunk costs associated with GenAI systems is necessary, as well as assurances that the investments are calibrated for long-term benefits. Stakeholders must also understand the timeframes involved, from the initial implementation phase to when positive returns can be expected. By managing expectations with clarity, the company can secure sustained commitment and support for GenAI initiatives.Performance monitoring and optimizationDetermine baseline metrics that act as a standard against which the added value of the GenAI system can be measured. Once the system is operational, the company must assess its performance, leveraging both qualitative and quantitative methods in its evaluation while utilizing appropriate metrics and benchmarks. For instance, the company might compare the output generated by the GenAI system against previously established baseline metrics, such as output produced by humans prior to when the GenAI system was implemented.In addition to monitoring technical GenAI metrics such as accuracy and precision, the company must measure the impact of the system through a business-focused lens. This means putting a spotlight on how the system influences business metrics, outcomes, and the overall impact on company operations. Realizing the potential of GenAI The potential of GenAI transcends simple enhancements in organizational efficiency. Its profound ability to generate, model, and interpret intricate data place it at the forefront of driving business innovation. GenAI empowers corporate leaders to envision a new horizon for their organizations, leveraging this rapidly advancing technology well past the bounds of simple gains in productivity. Through GenAI, businesses are not just improving processes, but revolutionizing their approach to problem-solving and strategic planning, planting the seeds for long-term value. Ryan Gilbert K. Chua is the Business Consulting Leader and Technology Assurance Leader of SGV & Co.This article is for general information only and is not a substitute for professional advice where the facts and circumstances warrant. The views and opinions expressed above are those of the author and do not necessarily represent the views of SGV & Co.

Read More
Leading the way in business

Other SGV News and Publications