註冊並分享邀請連結,可獲得影片播放與邀請獎勵。

Joshua Saxe
@joshua_saxe
Now: cofounder @ Abundant Security. Before: AI | cybersecurity @ Meta. Earlier: social science, classical/jazz piano, hacking scene
加入 May 2013
1.2K 正在關注    4.7K 粉絲
- It's urgent and indispensable that we fix AI cybersecurity policy now - I'm linking the slides from my keynote at the AI security forum below. I'm really passionate about the argument in the slides and I think the integrity of our social fabric depends on something like this happening soon. If you're reading this without knowing me until recently I was Meta's senior technical expert on AI security; I worked on frontier model evals, AI driven defense of Meta's infra, and was in lots of policy discussions with the other labs and the US/UK governments. From this I became deeply convicted that the frame policy folks are using to understand AI cyber risk is wrong from first principles; given where we're at in AI cyber capabilities this error will be very costly if we don't correct it. In the current frame, safety is imagined primarily as a property of individual models, and individual model launches are treated as the main objects of risk and the main opportunities for intervention (e.g. blocking a model launch). But the main object of risk is actually the softness of our entire national IT infrastructure (and therefore society) in the face of AI cyber capabilities, and the main object of intervention is to *increase the net benefits AI's dual use capabilities can offer to defenders while minimizing attacker uplift*. Government intervention should focus on using whatever methods -- AI or otherwise -- to mass inoculate society as fast as possible from the upcoming onslaught of cheap superintelligent hacking agents while also using these hacking agents to help do this and while minimizing their benefits to attackers. To be clear: I'm saying we should treat cyber risk as a public health concern and with an early-pandemic level of urgency. This would involve robust public infrastructure for surveilling the readiness of our economy and critical infra, understanding what's working for defenders and what's trending among attackers, and shaping policy at scale and with nuance around bending risk downwards. There are some efforts moving in this direction, notably those within CISA; but federal cyber defenders need to be empowered with more scope and scale and we need to go far beyond this. There are also important efforts inside the AI labs. But the labs can't impose regulations requiring, say, the boards and CEOs of tens of thousands of companies to properly fund the step change in cyber defense budgets that's needed right now. There really is an indispensable massive role for federal government and executive leadership here in keeping us all safe. After I gave my talk yesterday I did 1:1s with AI security folks from the labs, US CAISI / AISI, large AI safety grantmaking orgs, etc, who were in attendance. I think there's general agreement from our community here, and so a lot of this is up to our elected leaders, but perhaps there are ways the AI security community reading this can help catalyze this...
顯示更多
0
20
212
55
轉發到社區