Industry executives and experts share their predictions for 2024. Read them in this 16th annual VMblog.com series exclusive.
AI 2024: The Good, the Bad and the Ugly
By Gregor Stewart, VP of AI and Machine Learning Engineering, SentinelOne
In the past year, incredible change has been driven by artificial intelligence (AI): from playful new ways to create content, to the discovery of new materials. But we’ve also seen the havoc the technology can wreak – particularly in the cyberworld where we increasingly spend our time. It seems we can no longer trust what we read, see or hear, and as individuals and societies we face new forms of attack that we don’t yet fully understand. More change is on the horizon. What can we expect in the year ahead?
Hackers won’t break in, they’ll walk in
Generative techniques have come a long way. Weird syntax and tell-tale tone are gone, making classic attacks like phishing more compelling and difficult to spot. Employees will provide their credentials because the voices they hear will be familiar and the requests will be credible, essentially throwing the door open for threat actors.
Or the secrets may simply walk out
Generative models can be used to create personalized content that is convincing, especially in the moment, and attackers will use them to unleash a whole new wave of social engineering. Instead of going after vulnerable machines, they will go after vulnerable minds. The ability of government-grade adversaries to shape what people consume to guide them to act in ways they previously would not have countenanced, is a reality. Deepfakes and disinformation can turn employees and citizens into adversaries, and even more concerning, online intimidation can quickly spread and spark live threats and violence on a global scale.
And the calls may come from inside the house
Novel as they are, generative models are themselves vulnerable to novel attacks, and their creative nature can make compromise incredibly difficult to detect. These models are already at the heart of many of the most innovative products and are used daily by nearly everyone that has a device. Adversaries are busy poisoning these models and systems, by seeding the world with data that create exploitable flaws, when used in training or prompting. Of course, much the same AI is what enables them to do this at machine speed and global scale.
Governments will try to regulate AI, and companies will scramble to comply
The AI genie is out of the bottle. Regulators are chasing it and have already enacted policies that require companies to demonstrate greater control than they probably have. To comply, they will need to fundamentally shift their approaches to systems development and security. Paradoxically, regulation may make life easier for attackers, at least in the short term, as companies scramble to adopt the new tools and processes necessary to protect their employees and environments.
So hackers are using AI to craft more subtle attacks, to do it with greater speed, and even to destabilize AI itself; and they won’t have any regulations to deal with. It’s ugly, but that’s only half the story.
Fighting fire with fire
The same technology is also revolutionizing vigilance and defense: making it simpler to catch and design out vulnerabilities in code and configuration; to automate more and more of the high stakes grind of detection and response; and, ultimately, enabling human defenders to spend more of their time researching and devising new ways to better secure our world.
There’s a lot of fear, uncertainty and doubt surrounding AI. Rightly so. But 2024 will be a banner year for companies with the will and ability to bring these technologies to bear on the work of the SOC.
##
ABOUT THE AUTHOR
Gregor Stewart is the Vice President of AI and Machine Learning Engineering at SentinelOne. He has over 20 years of experience in software development culminating in deep domain expertise across data science, machine learning and AI applications. Stewart earned his MA in Philosophy, Politics and Economics (PPE) from the University of Oxford in 1995, his MSc in Philosophy and History of Science from The London School of Economics and Political Science (LSE) in 1997, and his MSc in Artificial Intelligence from the University of Edinburgh in 2009.





