Panel Discussion: Advancing Cybersecurity with AI and Machine Learning: Opportunities and Challenges
About this talk
This panel discussion explores the intersection of artificial intelligence, machine learning, and cybersecurity, highlighting both opportunities and challenges. The speakers introduce themselves and share their diverse backgrounds in AI and cybersecurity, with a focus on data privacy, vulnerability management, and user authentication. They emphasize that effective security is about managing risk rather than eliminating it entirely, and discuss how AI can help detect anomalies in user behavior and streamline security measures. The conversation also touches on the ethical implications of using AI, including concerns about data privacy and the need for transparency in how AI systems operate. The panelists conclude that while AI offers significant potential to enhance security, human oversight remains crucial in implementing these technologies safely.
Full transcript
[Music] ladies and Gentlemen please welcome to panel discussion about the topic advancing cyber security with AI and machine learning opportunities and challenges um I I don't want to waste too much of your time uh I'll just go straight to the point uh quickly introducing myself my name is Mari uh I am here representing my startup started in Finland a few years ago uh I'm here representing only
myself not representing any company or any affiliation with any uh work that I have done before quickly a background of about myself I used to lead a team of AI Engineers for medical application uh so that's uh about how critical it can be in terms of security uh I just want to get to know a little bit about our guests as well here in this panel so
how about uh we do it this way um I ask you to introduce yourself and tell us what you have done in the field of AI or cyber security or related topics and one line answer to this very interesting question which is what is the definition of security in your point of view now security for some people might sound like uh to go home safe it can
be not to get a physical harm right that's security as well to not sto my wallet that's security as well right so so what is Security in your opinion can we start with Z yeah so um my name is gtis as I've been working mainly in financial institutions or Banks uh maybe my security understanding is a bit spoiled but uh uh I tried to think about this
kind of what is the security and I'm thinking that mostly for my from my perspective it's enabling good guys to overperform bad guys and let the good guys to do the business stronger than bad guys without actually jeopardizing the ability to do so so you have to kind of stay invisible so when when when developers or users clicking buttons navigating through websites operating uh software they have
no questions am I doing right thing here so I think that's what security should do T great so my name is Gabriel I a software developer for long years now and uh somehow all of my career was around cyber security products but for the last year I'm working in a product which is a cross point between developers and security and I'm focusing in authorization or permission that
we give to the users in application and back to the question about what is security for me so I think security is mostly about minimize the uncertainity in our applications or in our our software in the Cross Point with ai ai is unstructured it's full with uncertainity so it became like a new world when it came to security how we take the unstructured data and actually secure
it to create more certainity in the application that we create amazing thank you yeah well um I completely agree so my name is kir KOTV and I'm the founder of kikimore iio and soul cyber uh the more interesting one is kikimora IO which is a vulnerability management platform and orchestration too I've been dedicating my last few years on this one I started doing cyber security when I
was 14 so that's like 15 16 years already um I think security is managing the the risk because nowadays a company should not pay more in cyber security then their their their data is worth it imagine you have hundreds of systems and thousands and thousands of vulnerabilities right how do you actually manage everything well security is not about fixing it all you can't that's simply um an
answer so it's about managing the small risk and reducing the risk to a level which is completely manageable by the organiz iation how with the help of AI I think by actually utilizing all the different sources we have about the priority of our Assets in the company about the current level of hardening of our systems about trade intelligence feeds so that we can en enrich our current
vulnerability uh static data so I think we can use AI to connect all the dots out there all the sources and make our data meaningful to the specific organization that we're trying to protect hello my name is Kristoff or you can call me Chris if it's too difficult to pronounce it's it usually is and I'm a Solutions architect and chief of data engineering department in zebia Poland
uh zebia is a global uh company uh from doing consulting and software development uh for in any technology starting from no code uh to all the coding Solutions and these kind of things but my background is primarily on software development and devops and uh I'm uh mostly focused in my uh security area in data privacy uh by the way I have tomorrow I talk about data privacy
in the cloud but this means that I'm also defining the security in a little bit different way I'm not saying that your definitions are wrong don't don't get me wrong but this is like a complementary definition when I'm focused basically on the user security so that they feel safe to so the good guys uh are are secure on on our in our applications in in our pages
and using AI to to provide or to deliver the security for all the users in in applications is my primary Go amazing thank you uh so I noticed a pattern here uh many of you talked about data security in terms of how to structure the data and findings and how to understand I mean we all have logs but can can I know in this log that there
is an issue so so can someone shed a light on actually what is that exactly and what AI can help us with that maybe I could um talk a little bit more uh about this one and when we're talking about AI machine learning it's usually something people think like it's kind of happening automatically everything is settled up Etc and it everywhere in every you know cell phone
on your computer or something but as far at least my experience when I was working in in uh quite uh big banks in in in Europe it's it's kind of barely visible for regular user and people very careful in financial institutions to get into AI uh about the Privacy topics about actually what the outcome can you rely on let's say testing application with code with a with
a AI is it trustworthy but it could help it could be a good start it could be you can reveal some some things my my main topic about let's say coming back to the logs is that mainly I would say not even call it AI but machine learning where you're actually learning the habits of the users and then by reading count can you can detect anomalies that's
something already exists you can't uh you know um argue that it's it's in know most of the seam tools that you can have machine learning but what I saw happening in in uh big security corporates that are offering tools and actually developing them at least it happened like half year ago they're looking into tailoring security for each individual user based on their uh behaviors so I think
a lots of value of that when when you're thinking about security Baseline configuration so it's something that you're giving for all as a minimum and then uplifting let's say something working we have credit cards and we have up uplifting hit security but then you have second Baseline which you need to manage that than than the legal department HR you need to different levels of security what AI
does is actually analyzes the the behavior of each user and applies dedicated security policy based on what he used to do last month and he if he does something very differently next month he might get trigger alert so that's why I think it's it's kind of useful to to have this combination of machine learning and I in in analyzing logs and that's a very important point when
you said tailoring for user uh are we talking here about a a a human person tailoring for each user uh it might be different topics how setting up your security if that's user Centric it might be be user if had data Centric let's say which data you operat it might apply security controls on data assets like if you have pcidss servers it's it's might be tailored to
those and it might be user per per entity within identity access management system so it depends how we monitoring and of course question how security vendor is going to develop that I'm not in involved in that unfortunately amazing uh but in terms of uh logs again if we go back I have bunch of logs and I have bunch of data I still want to can I use
AI today to to to tell me okay this data sounds like there is a bad actor the bad behavior someone trying to attack me what are the tools or what can I do to to to understand yeah so I think we should not um actually focus on the tools but rather on the data sets because yes a ml enables us to have a lot of data from
different sources so in the past we we were only able to detect anomalies based on some static data set but now the AI actually allows that you pull information from a lot of different thread feed sources a lot of different logs out there in the network you're you can actually pull data from the users so if I'm uh having some traffic right now I have an application
which is running and is doing something I'm generating traffic and this traffic goes somewhere with a third party so right now with the help of ml I can actually collect every single user's data and I can look for some anomalies in in in everybody's data which was not possible in the past when we didn't have machine learning we could only rely on static databases with weaknesses vulnerabilities
and anomalies right so right now we basically if I'm browsing something on my phone I'm generating very useful data and usually I I give my my consent for this data to be analyzed by third part is including uh threat into feed providers so now I can have a realistic data almost real time data about um a vulnerability a malicious code something which is infecting my system this
will be replicated in in a matter of minutes to all the third party vendors out there so if I'm using trinto tools uh and lo like CM uh solutions they are so accurate already and almost they they work on the go so as something is happening it can already be replicated to my network to protect me yeah amazing so so when you mentioned real time detection I
imagine that we are relying here on 100% on AI or an automated machine now the the famous question chicken or egg how can I know that this system doing AI in itself is not attacking me how can I make sure that this model in itself is safe well you always have some fault tolerance so you can never be 100% certain about this however how ml works is
it's taking it works with voting so if you have more than if you have Quorum on some decision then uh apparently this is the reality this is the valid answer yes there is uh some mistakes sometimes but if 95% of the users are not detecting this system as a Rog device an attacking system then I I should consider it a safe system right it might be in
this 5% tolerance it might be that sometimes this system will be a malicious one but in reality it's actually helping me so much more compared to um the impact can I I can have from this 5% so we should apply the 8020 rule I can save such a pain by actually utilizing this technology and even even though sometimes the results will not be accurate it's still I'm
still going to benefit from the the machine learning technology so I I think yes you can never be certain because it's a matter of voting so if you find a way to hack the vaulting mechanism so that you can change the Quorum well yes you can make a real system look as a malicious one or the opposite I want to connect both so the point that you
mention so you mentioned the it's hard to adopt AI for some especially Finance system and you mentioned the dangersous of the bad parts of AI and do remind me the way that we move to the cloud right so when we move from onpl to the cloud there were a consumption that financial and Healthcare System will be the latest to move because they Afraid from that they don't
know what is it and we see that the same with AI for many people especially non-technology people AI seems like a magic like a miracle they don't understand how things working and I think as cyber security expert what we need to do is invest in education what is behind this sayi at the end this is data this is algorithms that runs on this data there are no
magic there there is holic conation there are things that are not true but there are no magic it's at the end is science it's math right and the same as I have love this meme about the cloud it's not the cloud it's just someone else computer right and the same we need to do about AI it's not AI it's about data it's about data sets it about
thing that we can expect that we can monitor that we can detect that we can predict and we need to look at that the way that is help us right and the way that we can enhance security with that and not afraid from the vulnerabilities because it's just about educating better how to look at the right of these architectures but I I would like to add something
to to what you said because uh it is quite important to say that everything is about the quality of the data for machine learning it's not like you said it's not a magic blackbox doing something it's just a model built on the data and if the data are correct I mean if they're correctly like we say labeled so we know what is actually malicious and what is
not then it's okay but there is additional problem to that because because we can uh easily expect that there are out there a lot of tools that are doing these kind of detection or prevention mechanisms like out of the box so we just put a tool into our landscape and it works it will detect all the malicious things and then we can sleep well we can like
fire all the security guys because we have this tool but that's not true the thing is that usually these tools are built on data provided by someone else correct and your systems or our systems are usually uh specific it's not like everyone builds the system in the same way and uh I had a nice conversation with one of my colleagues in a company building a financial system
and he said he would like to have a tool that detects the uh potential uh attacks on their financial data and he would like to have a tool that does at least a triage to say this is super malicious this you can leave for for later or this is like 10% it's it's it's it's a it's an an attack but he had to build the model himself
because the uh like off the shelf tools did not provide a good quality the quality that he expected at the end of the day so uh my conclusion is that once we understand what this magic black box is and once we understand how to build models on top of the data once we investigate the data understand them uh make the correct leling or doing a lot of
things beforehand then we can build a model which is additional task and then we can we should also or we must basically monitor how it works in reality does it detect the malicious attacks uh all the time or maybe it's degraded over time or something like that so it's all about data and all about the math that you mentioned G yeah I think that's actually a great
point and I think it's a a good time to emphasize a tool that actually could help with that so there is for llm there is rug retriever augmented I can't remember the G but the rag layer could actually help you even if you have an llm model if you have a model that you're not sure what data it was trained for if you're using rag on top
of it you can get the augmented re resources for this one and I think for everyone who try to get the unstructured data and want to make sure about security so creas Point are great make sure your data has the right quality and you not must uh you not must have sure that the llm model quality is good because that the the predictable result could you know
just make you the sense of the quality of the data if you want to add another layer so rag is a great point to from yeah sure um uh the the G is for Generation generation the trial augmented generation yeah but uh you could use the first point and the most important one is for me always to emphasize that Ai and ml basically what what you uh
gtis has pointed out is machine learning is something different from gen in terms of Undercovers gen is machine learning but usually when we try to make a prediction or a thread detection mechanisms we build our models or utilize the ready to use models but we can fine-tune them in a in a simple way or maybe not simple but it's it's like understandable for us well for genni
we usually use the third party Services where we only send the query and get the results we basically most of us don't build llm uh uh so large language models because it's super expensive requires tons of data much more than for the typical uh machine learning model but the thing is that that if you provide the augmentation to The Prompt so you say something like uh for
instance where I'm uh trying to do this kind of things this is my terraform script defining my infrastructure please uh try to predict where the potential thread surfaces uh in this infrastructure is this you can try this out this this is pretty easy if you have a model uh which has a quite long context this is uh retrieval augmented generation at some point but but the thing
is that this model we have to understand that these large language models are basically built on the knowledge that was previously on the Internet or somewhere else which is a public one but the so the answer will be based on our context so on our infrastructure description and the knowledge that is available for public so the suggestions might be good but you cannot over rely on these
answers you have to analyze it yourself as well because these answers will be basically what you could find on stack Overflow once and now I I usually said that chat GPT is a stack overflow on steroid so this is pretty much the the the thing so you could use these tools but don't over rely on them uh just check yourself everything but this is just a good
start for for using these kind of patterns that you mentioned yeah right I I found a a pattern here where basically everyone is putting a percentage so my my question is are we there yet I I want to clarify I I think most of us here are asking this question uh can we can we just go tomorrow and rely on AI but now all the experts are
telling me there is a percentage of risk I mean let's let's face it I'll go to a bank or financial institution and tell them uh well using AI you will have le less cost more efficiency and everything but there is 1% chance that you will get attacked and lose money you think they will accept this what what can I do in this 1% or 10% every one
of you mentioned a percentage of of risk so so if if I want tomorrow to go and apply AI for U for security uh what are the mitigation for those unhandled risks ju just a quick sentence all everything we do we do to avoid risk not to remove it you cannot do that yeah so um I would say that uh very is quite simple assessment I would
say if you have 1% what does it mean for a company will that break you how fast and how often so when you have a liting assessing uh applying the criticality then if you want to apply mitigation actions human person next to the I skilled human person might help things out and when I'm thinking about what you've been talking is actually maybe not that like an scientific
matter related to AI but it's often next to cyber security and when I see something relying purely on AI it's I I don't see that secure uh I always think that uh AI is a data that you don't have so that's where you could benefit and leverage AI is actually you creating something investing your work and your data and in part you injecting what AI actually enriching
it incapability wise it's advising you it's uh adjusting the code it's suggesting fixes something like that not creating for you it can only inject something like you can request how what do you think about my code what do you think about feature about this function uh and and that can help and same security detection like what do you think about this alert can you tell me more
about this cve about this vulnerability and then you're getting enrichment and suddenly you can understand that because it talks in c-boy language with you how this threat can be exploited Etc so I think that's how you can look at look at it it's enrichment it's not so your answer is we are not there yet we still need a human factor I well the results to check results
of manually analyze and make decisions uh yeah I would say at least you're manually creating your checks and then you can automate your checks end in life yeah we in line with our policy we in line with risk appetite but purely no I wouldn't at least not in the bank I wouldn't rely AI not yet I was allow to support are you using something else so my
my question on this one is quite short and simple so without utilizing AI let's talk about signature detection about detecting events and anomalies without utilizing you AI you have this amount of data with 100% certainty yeah if you are using MMO it means that you're collecting data from here and there in the other source so you're collecting a bunch of data so you have that much data
with 90 6% certainty so I'm asking is it better for me to know about with 100% accuracy that these are the potential risks for my company or is it better to have 95% certainty but from something much bigger and I have so much more data which I can make meaningful meaningful to my organization yes there's always going to be with the one to 1% uh tolerance but
in this 1% yes mistakes happen but it's so much better for me to know that I have that amount of risk and eventually there will be this amount that it could be fake data then knowing just this one with 100% amazing uh yeah I want to add to that that a question do you think that applications with non AI are safe are free of sec security bug
right at the minute you write your first line of code you create security vulnerabilities and the answer for that it doesn't matter if it's software if it's machine learning data science AI is about educating developers I have a story um I ordered a flight a week ago and the I did it in the airline company website and I tried to pay with American Express but American Express
CVV the numbers on the card are four numbers not three no all the card the three number is four and I tried to pay it and it blocked my pay because it say the number is not valid I need to put three three digits so I open the developer tools as any good developers and I found that they are using a third-party fraud detection provider that blocked
me to pay so the fraud detection provider create a security vulnerability so I notifi them and I have a friend there and someone called me and say ah it's not a bug and I told them yeah yes this is a bug if I cannot pay or if I can pass it because I pass by it I pay I found the way to pass the fraud detection frontend
validation right and so developers I actually expected this like when you when you said you open that developer tools I definitely said okay you increase the character count or something yeah so so the thing is security is about educating so developers that educated about security create better application so we need to invest more time in educating developers on the security vulnerabilities with AI and then we can
get it involved better in the application and I want to get for a second to so Chris uh made a little distinction between machine learning which is more about doing uh Magics on data and geni which is more about doing things that um impossible the the the one of the distinction between machine learning and geni is the con consumer of it so usually when you do data
science when you do machine learning you know about data you know about algorithm you know about how to process data and then you're more aware to the dangerous point that you have there right the the problem with geni the problem with modern AI is that the consumer they not aware about what could be the security issues and this is why in one hand it's getting hard to
adopt that because the usual developer some of us even don't know about Security in just regular programming languages they're really afraid of that so we need to First make sure that the data itself in the machine Le learning phase is safe enough but we need to invest time in educate how to be more secure in the Gen in the uh generation after yeah the the problem well
maybe not the problem but the the challenge is that usually when you have a data science team that develops the machine learning model they know what they do MH and the people that use jni usually they don't know what they use exactly and I found one interesting splank report that said that 91% of the security guys or cyber security teams are using gen at some point in
some form maybe just generating the terraform code to create Aurora myql I don't care but this is like they are using it but at the same time 65% of them do not absolutely understand how it works under the under the hood and this is like a typical one because under the hood of the genni algorithms is a typical machine learning models we all heard or probably all
of us heard about neural networks uh which is like an algorithm one of the machine learning algorithms under the covers gen are neural networks is the same but the the interesting part is how they are architecture how they are designed to do these magic things that we think are magic so it's like not the time for a but do you think do you think that users should
actually who are using jni have to understand how it works and where data is coming from do they really need to have deep understanding that there is machine learning behind it I don't think it should be a deep understanding I think it should be a conceptual understanding of how it works or because people usually there are a lot of discussions on the internet will AI kill us
will AI replace all the developers in the world uh will AI rule the world and these kind of things and uh well this is not true because if you understand how geni works you know this is just an a probabilistic mechanisms predicting single words one by one and that's all and I have a comment to this one I'm not sure have you heard that the EU just
passed the regulation EU AI act which actually much stronger than gdpr when you when you think and it's very much related to the privacy about person safety and especially about Modern Warfare that you the the AI gen can't create contents uh you know seek or or identify persons one after another in cctvs ETC all about those protections so those canot be produced and I think that's a
response to what you're saying that they not destroy us no other people destroy us because AI instructed them to do us exactly J is a tool caned this is the same with software development you can create an application that allows you to book flight with your four digits c c but at the same time you can create a virus that will Ex like make around somewhere or
something like that so this is just a tool nothing more okay I think at this point uh we we cannot skip a very important topic about ethical and responsibility when when using these kind of things so I want to just share quickly a quick story um about a bank by the way it's it's a real story a bank that wanted to enforce their security so what they
do is basically uh whenever you open the application and you start to use it on your phone basically they open the camera to check that the face of the person in front of them is actually the biometric information of the user that they have on file which sounds like super safe that's making me feel secure because I know now that nobody else on the planet can use
a bank except myself now think about it one more time that is actually not ethical they didn't ask for permission to open my camera what if okay I'll let your imagination what if right so and I have no idea what they are doing with my photo I mean they will tell me okay I'm I'm just using your photo to build and and and train my system but
did I allow you did I accept that now believe it or not in I don't have numbers but most countries in the world whenever you go to an ATM you are actually being filmed and they are actually actually filming you even without telling you so this is actually an a habit happening everywhere now let's let's cust it into our system let's cust it into uh building and
using AI what is uh what is responsible what is the ethics of using AI when we are trying to secure our users with good intention so um now I maybe repeat a little bit you directive that is instructed is actually you either have a consent that's the one so to for or either have a directed purpose so meaning if you searching for criminal uh the same way
identifying user in front of ATM you do not identifying who came but you authenticating that came the exact person so if Bob came to there ATM but you're looking for Jeff you're just checking it's not Jeff it's not Jeff it's not Jeff that's Jeff allowed to P so so you can't identify that's not ethical you can't put the name next to the random person who just walks
by but you can say with AI is that correct person is that's a match with the person who gave me content that's ethical so you and what is risk if I identify uh privacy risk you might get fined Etc that's a protection of a of a uh privacy of a person so it's my it's in Europe if we talking about us or China it might be very
different in let not go politics yeah I I actually wanted to expand on the the China matter because what you explain is indeed the case in in Europe and uh like the the local countries let's keep it country agnostic there are other country in Asia other other countries not mentioning China so uh where so there is indeed other countries where you can where you have an AI
scoring system so if you're walking on the street you get detected and you have a certain score applied to your behavior if you're helping an old woman to cross the uh the road then you get positive points if you are um overtaking someone or driving on a red signal you get bad points at the end you have to pay bigger or smaller Insurance depending on your scoring
system so it's like a behavior based scoring system uh and I think that's scary already when you combine it with the capabilities of machine learning that's already getting scary uh but I think for the rest of the the use cases am I allowing to to be identified with with my am I allowing the application to use my camera yes I do by installing the application I actually
agree to using this application according to their terms and uh conditions and uh there is a policy of use and I accept the policy of use and only then I can start using the applic how about 20 years ago when you were providing your ID card so that they can copy your ID card right eventually with your um ID card a copy of your ID card or
a password passport they can go and um have a credit on your name so is it not the same it's just another dimension now we're still using data someone's data someone's uh um we're still authorizing someone by some criteria but it's just a more modern criteria nowadays and so you're saying I have to always read the terms and services till the end all the 9565 pages yes
and yeah just I'm sorry for Interruption but just regarding this point um I feel like even if I authorize the application to open my camera uh I need every single time uh that they told me that I'm about open your camera now so um I think that's a European thing but let's not go there yeah it it's always a matter of usability versus security so I can
imagine what the usability will be if you have to to consent everything every single time yeah but I think um to comment on this one I think it's ethicality of usage is very much driven by by our regulations where you operate uh what kind of regulations Alles for your industry is it card industry is it is it uh military Etc so but sometimes this ethical versus legal
is it's not the same sometimes so so I think we're almost on time so anyone want to add about responsibility and ethics for AI I might add that I'm an engineer sorry not about that I I'll just say that they mentioned the PO that is scary I'll mention that not scary again people are scary but also AI open a lot of opportunities to being better humans right
you see the jobs that AI created you see that literally people improving their life in poor countries by being prompt Engineers is not funny it's create opportunity it's create Mobility it's create uh an opportunity and a chance for a better life so it's not just scary it's also have a another side for being more ethic for being better persons to each other so I'm full with hope
I second that thank you um do do we have time to take questions or okay so I think it is that point when we look at the audience Again full room that's amazing uh and I'm I'm pretty happy to take your questions if you have any yes please go ahead oh oh really uh how can I read that no way I can read that can you let
me try so what about transom whereare attacks that bypass normal user access security how can AI enhanced security help to prevent such attacks so isn't AI already can create a ransomware intelligently for me so that's it's at the beginning all right so who who wants to take this question how can I AI enhance so I talk about security or you talk about access yeah I think there
are two two perspective for this question the first one is we are going to deal with more and more non human identities right we're speaking about AGI we're speaking about uh the machine or the the robots or whatever it is they are already there they're already here right in my application I have identities that are not human and we need just you know to to go over
it to understand the patterns to understand the thing and understand the the the abstract meaning of identities that we haven't built security mechanism for them right so you mentioned Biometrics that a way you know to create more and more protect from the access perspective and I'll let get his answer from the security perspective um AI will not prevent itself that's what I'm was my opinion there are
races between AI generated fishing males and scam versus AI protection in the email which uh at the moment seems like in parity you can't say that one or another wins so you can't with AI detect that message that you got is AI generated that's almost impossible at the moment however AI could prevent uh as I mentioned by tailoring uh protective tools RS and uh then enabling operating
system or or uh EDR to not allow automatic alteration of the of the folders data Etc so you can't encrypt them just because you got there so that's how a AI just can enable for particular user those controls because he never touch I don't know operating system drives or or it it doesn't touch them in automated manner only manual just clicking documents Etc that allowed automated no
so AI can enable protection for user that's how I would do that and on the other side when uh AI is used for attacking then it can also adopt so a malicious code nowadays can adopt quickly based on the the the protection so if if the the malicious code is getting stopped somewhere by the EDR for example then it's getting back to the command and control server
and it's modifying itself it's mutating on on the go so that it can go undetected and infect your system so it's always going to be a matter of good news but I'll be talking about this one during my lecture later today all right uh thank you for your answers uh I'll check quickly if there are other questions oh there is another one geni well yeah definitely we
need to talk about gen at some point so gen is also improving for circumventing security me measures think generative deep fakes against Biometrics what do this cat and mouse game well the the thing is that it will be it is the same story it's always like we have some stuff that can generate the faces of people that do not exist and then they can be used for
uh for doing some security attacks but at the same time we are developing models models gen based models that are able to detect if this pH was artificially generated but you never know it's like uh I have one always uh tell one interesting story when we started to generate some content and then we tried to check if it's AI generated and some Detectors of course existed on
the market but uh when we put the text AI generated it said it's 95% AI generated but when we just removed one comma it said it's 100% human written because it was a mistake so uh it assumed that it's is a human generated thing so this is a race of course there are new methods new architectures not only based on llms but for the graphics there are
different algorithms I could speak about that for two hours without a break so don't don't tempt me but the thing is that uh we always try to create new algorithms that are able to the detect if something was a generated and then apply the General Security rules for that because at the end of the day both gen and ml is just a tool nothing more and also
yeah maybe are you trying to instruct uh attackers to modify and make mistakes yes and this so that they can fool the system let let me stay on the safe side but yes this is usually I don't think I don't think this is a taboo to discuss this because we need to not sure but it it is usually used for trying to cheat on to to to
try to uh overcome the the difficulties or the the algorithms that are trying to detect if something is aen generated so we just introduce small mistakes and try to like make these algorithms stupid but at the end of the day the the the creators of these algorithms are trying to be uh like to find these kind of things and say well they are trying to cheetah so
this is like a Race So maybe one more comment just Back to Basics add password next to be next to your face recognition and suddenly yeah that's him but he doesn't know password multiactor authentication I with help amazing um I think now I can see the questions here so yeah yeah it's very convenient yeah uh can can we move to next question if there are any that
was there oh we're over time okay so uh I think I think at this point I would love to thank you so much for for joining us and sharing your expertise last today uh that was great to have you and thanks for the great audience and for your uh attention uh with that let's conclude and uh enjoy the rest of the conference thank you thank you guys