<p>The recent Hugging Face-OpenAI incident is raising questions about how to secure AI as it becomes more autonomous and integrated into business operations.</p>
<p>During a controlled security exercise in mid-July, OpenAI models <a href="https://www.techtarget.com/searchsecurity/news/366646105/OpenAI-models-escape-containment-hack-Hugging-Face">accessed systems they weren't supposed to reach</a> by exploiting a vulnerability in the surrounding infrastructure, eventually reaching the Hugging Face AI development platform.</p>
<p>The incident has challenged assumptions that isolation and <a href="https://www.techtarget.com/searchsecurity/definition/sandbox">sandboxing</a> can sufficiently protect AI systems. Yet security experts say the bigger takeaway is about whether businesses have properly implemented fundamental security practices such as identity and access controls, monitoring and containment.</p>
<section class="section main-article-chapter" data-menu-title="The sandbox worked — the environment didn't">
<h2 class="section-title"><i class="icon" data-icon="1"></i>The sandbox worked — the environment didn't</h2>
<p>"The sandbox worked exactly as designed," Jen Waltz, founder and CISO at Imajenative, a Chicago-based IT and cybersecurity consultancy, told TechTarget Cybersecurity. "Unfortunately, the environment around it did not. That distinction is the whole lesson."</p>
<p>In the Hugging Face-OpenAI incident, Waltz added, AI didn't reinvent the wheel; instead, it showed how quickly an AI system can exploit existing security weaknesses if it has a goal and access to pursue it.</p>
<p>"AI didn't invent a new class of attack," she said. Rather, it executed the old ones at speed, before human operators noticed or stopped it.</p>
<p>"I do not agree that this challenged traditional sandboxing assumptions," echoed Rich Mogull, chief analyst for the Cloud Security Alliance (CSA), when we asked him about the limitations of this approach to security. "What we saw was a sandbox with a hole, and a system that appears to have been unmonitored."</p>
<p>The takeaway for CISOs: Don't abandon traditional security controls; instead, ensure you're <a target="_blank" href="https://www.darkreading.com/cyberattacks-data-breaches/hugging-face-hack-lessons-cyber-defenders" rel="noopener">applying them effectively</a> as AI systems find new ways to gain access and take more actions on their own.</p>
</section>
<section class="section main-article-chapter" data-menu-title="Steps CISOs should take now">
<h2 class="section-title"><i class="icon" data-icon="1"></i>Steps CISOs should take now</h2>
<p>CSA this week issued a <a target="_blank" href="https://cloudsecurityalliance.org/artifacts/hugging-face-ciso-post-mortem" rel="noopener">post-mortem report</a> on the Hugging Face-OpenAI incident, recommending three steps for CISOs to take to prepare for <a href="https://www.techtarget.com/searchsecurity/feature/AI-powered-attacks-What-CISOSs-need-to-know-now">AI-driven incidents</a>.</p>
<blockquote class="main-article-pullquote">
<div class="main-article-pullquote-inner">
<figure>
What we saw was a sandbox with a hole, and a system that appears to have been unmonitored.
</figure>
<figcaption>
<strong>Rich Mogull</strong>Chief analyst, Cloud Security Alliance
</figcaption>
<i class="icon" data-icon="z"></i>
</div>
</blockquote>
<ol class="default-list">
<li><b>Now:</b> Identify and secure AI agents that are at the highest risk. Limit unnecessary permissions and confirm teams can shut down risky activity.</li>
<li><b>This month:</b> Monitor AI behavior and make sure systems can recover quickly when something goes wrong. Deploy and test <a href="https://www.techtarget.com/searchsecurity/tip/Top-deception-technology-vendors-for-active-defense">deception technologies</a> and AI incident response processes.</li>
<li><b>This quarter:</b> Prepare for AI incidents before they happen by assigning responsibility for AI systems to someone who will respond when they behave unexpectedly. Run AI tabletop exercises and deploy system-wide deception technologies.</li>
</ol>
<p>A major challenge for CISOs is how <a href="https://www.techtarget.com/searchsecurity/opinion/Identity-security-for-AI-agents-The-proliferation-challenge">quickly AI systems are becoming connected</a> to more tools and information. Security teams need to know what they can access and how to respond when AI doesn't behave as expected.</p>
<p>SANS Institute recommends that security leaders reconsider how they manage AI systems as those systems gain access to sensitive data.</p>
<p>"An agent is not a user, and it is not a service account," said Rob T. Lee, chief AI officer and chief of research at SANS. "It is closer to a brilliant intern with infinite energy, no instinct for boundaries and whatever credentials you handed it."</p>
<p>While AI providers continue to improve built-in safety measures, Lee cautions
<p>During a controlled security exercise in mid-July, OpenAI models <a href="https://www.techtarget.com/searchsecurity/news/366646105/OpenAI-models-escape-containment-hack-Hugging-Face">accessed systems they weren't supposed to reach</a> by exploiting a vulnerability in the surrounding infrastructure, eventually reaching the Hugging Face AI development platform.</p>
<p>The incident has challenged assumptions that isolation and <a href="https://www.techtarget.com/searchsecurity/definition/sandbox">sandboxing</a> can sufficiently protect AI systems. Yet security experts say the bigger takeaway is about whether businesses have properly implemented fundamental security practices such as identity and access controls, monitoring and containment.</p>
<section class="section main-article-chapter" data-menu-title="The sandbox worked — the environment didn't">
<h2 class="section-title"><i class="icon" data-icon="1"></i>The sandbox worked — the environment didn't</h2>
<p>"The sandbox worked exactly as designed," Jen Waltz, founder and CISO at Imajenative, a Chicago-based IT and cybersecurity consultancy, told TechTarget Cybersecurity. "Unfortunately, the environment around it did not. That distinction is the whole lesson."</p>
<p>In the Hugging Face-OpenAI incident, Waltz added, AI didn't reinvent the wheel; instead, it showed how quickly an AI system can exploit existing security weaknesses if it has a goal and access to pursue it.</p>
<p>"AI didn't invent a new class of attack," she said. Rather, it executed the old ones at speed, before human operators noticed or stopped it.</p>
<p>"I do not agree that this challenged traditional sandboxing assumptions," echoed Rich Mogull, chief analyst for the Cloud Security Alliance (CSA), when we asked him about the limitations of this approach to security. "What we saw was a sandbox with a hole, and a system that appears to have been unmonitored."</p>
<p>The takeaway for CISOs: Don't abandon traditional security controls; instead, ensure you're <a target="_blank" href="https://www.darkreading.com/cyberattacks-data-breaches/hugging-face-hack-lessons-cyber-defenders" rel="noopener">applying them effectively</a> as AI systems find new ways to gain access and take more actions on their own.</p>
</section>
<section class="section main-article-chapter" data-menu-title="Steps CISOs should take now">
<h2 class="section-title"><i class="icon" data-icon="1"></i>Steps CISOs should take now</h2>
<p>CSA this week issued a <a target="_blank" href="https://cloudsecurityalliance.org/artifacts/hugging-face-ciso-post-mortem" rel="noopener">post-mortem report</a> on the Hugging Face-OpenAI incident, recommending three steps for CISOs to take to prepare for <a href="https://www.techtarget.com/searchsecurity/feature/AI-powered-attacks-What-CISOSs-need-to-know-now">AI-driven incidents</a>.</p>
<blockquote class="main-article-pullquote">
<div class="main-article-pullquote-inner">
<figure>
What we saw was a sandbox with a hole, and a system that appears to have been unmonitored.
</figure>
<figcaption>
<strong>Rich Mogull</strong>Chief analyst, Cloud Security Alliance
</figcaption>
<i class="icon" data-icon="z"></i>
</div>
</blockquote>
<ol class="default-list">
<li><b>Now:</b> Identify and secure AI agents that are at the highest risk. Limit unnecessary permissions and confirm teams can shut down risky activity.</li>
<li><b>This month:</b> Monitor AI behavior and make sure systems can recover quickly when something goes wrong. Deploy and test <a href="https://www.techtarget.com/searchsecurity/tip/Top-deception-technology-vendors-for-active-defense">deception technologies</a> and AI incident response processes.</li>
<li><b>This quarter:</b> Prepare for AI incidents before they happen by assigning responsibility for AI systems to someone who will respond when they behave unexpectedly. Run AI tabletop exercises and deploy system-wide deception technologies.</li>
</ol>
<p>A major challenge for CISOs is how <a href="https://www.techtarget.com/searchsecurity/opinion/Identity-security-for-AI-agents-The-proliferation-challenge">quickly AI systems are becoming connected</a> to more tools and information. Security teams need to know what they can access and how to respond when AI doesn't behave as expected.</p>
<p>SANS Institute recommends that security leaders reconsider how they manage AI systems as those systems gain access to sensitive data.</p>
<p>"An agent is not a user, and it is not a service account," said Rob T. Lee, chief AI officer and chief of research at SANS. "It is closer to a brilliant intern with infinite energy, no instinct for boundaries and whatever credentials you handed it."</p>
<p>While AI providers continue to improve built-in safety measures, Lee cautions
[…]
Content was trimmed to protect the source. Please visit the original article for the full text.
This article has been indexed from Search Security Resources and Information from TechTarget
Read the original article: