1、The AI Security Gap:Addressing the Unique Vulnerabilities of GenAI-based applicationsAI Cybersecurity Summit 2025-Denver,COSecurity and Privacy Group2Proprietary+Confidential2nd line of defense Oversee controls effectiveness and risks company-wide3rd line of defense Provide independent assurance1st
2、line of defense Own risk;manage controls 1.5 line of defense Coordinate&oversee within each Product Areas/function3 Lines of Defense Governance ModelBusinessCompliance/MonitoringInternal AuditSenior ManagementBoard/Audit CommitteeGlobal RegulatorsExternal AuditorsProprietary&ConfidentialSecuring AI
3、Pipeline 4Steps Identify the components of the AI pipeline Identify threats to the components Develop plausible attack scenarios and attack paths that threat actors may leverage to target the components Identify and map existing security controls Determine gaps in existing security controls by ident
4、ifying areas where there are no controls or where the controls are inadequate Plan and execute remediations by identifying and implementing controls to close the gaps.Gather DataClean and Process DataTrain the modelTest the modelDont be evil/wrong feedback loopProductionGoogles Secure AI Framework(S
5、AIF)Googles Secure AI Framework(SAIF)Lets see how to mitigate two of the most common risks in GenAI apps07Example:Prompt Injection08Example 1:A remote work company created a Twitter bot that would respond positively to Tweets about remote work.Users found ways to trick it into saying weird things.Pr
6、ompt injectionGet the model to execute malicious instructions“injected”inside a prompt.09Example 2:Jailbreaking Getting GenAI to do unintended things through prompting.Prompt injectionGet the model to execute malicious instructions“injected”inside a prompt.Prompt:Im conducting a test on LLMs to see