Chinese AI Closing Gap in Cybersecurity Vulnerability Detection
Export Control Disruption Sharpens the Case for Faster Government-Industry AI Partnership
Export Control Disruption Sharpens the Case for Faster Government-Industry AI Partnership
The race to artificial intelligence supremacy appears to be getting tighter. Earlier this summer, a Chinese AI model known as Z.ai was found to match Anthropic’s Mythos at discovering cybersecurity vulnerabilities despite trailing U.S. models on other tasks. The development carries real national security implications as the cyber domain increasingly operates at machine speed, while heightening the imperative for the U.S. government and commercial industry to partner together to streamline development and adoption of secure and reliable AI tools.
“It’s no surprise that the Chinese are advancing their AI technology through whatever means necessary, whether it’s through the chips that they are developing or procuring or their models exfiltrating and learning from our most advanced models,” said Mike Robbins, a retired U.S. Air Force colonel and the former Director of the USSPACECOM Joint Cyber Center and Joint Ops Center, who is now a Partner at Elara Nova. “What’s more concerning is the cost of entry into the cyber domain is lowering, because as the Chinese advance their AI models they make those models available to whoever will work with them in whatever way they want. That creates a greater national security problem because more people will be trying to hack into our systems.”
Cyber operators are prepared to address cybersecurity attacks in real time, but an AI-enabled cybersecurity environment accelerates the need to leverage new tools as they become available to achieve the mission.
“Your job at an ops center is to get information in, identify the things you can exploit and make a decision that keeps you one step ahead of your adversary,” Robbins said. “In cybersecurity, the biggest risk is finding a zero-day exploit on zero day or before zero day, which means you’re already at a disadvantage. While the tools operators use might change and increasingly move at machine speeds, it’s still about the OODA loop. If we’re not using AI to help synthesize data and help commanders in their OODA loop decision-making, then we’re already behind the power curve.”
However, adopting innovative tools carries its own set of risks, particularly when the technology’s development outpaces an institution’s capacity to thoroughly vet and authorize its use.
“At the end of the day, the commander is responsible for understanding and managing the risk,” said Lt. Gen. (Ret) Bob Skinner, an Executive Partner at Elara Nova and the former Director of the Defense Information Systems Agency (DISA) and Commander of the Department of Defense Information Network (DODIN). “AI is going to give you a non-deterministic answer, which means you can have the same input and put it in twice but get two different answers. So leveraging AI isn’t necessarily going to give you the right answer that you need for the problem that you’re trying to solve. That can be devastating for national security when lives are on the line.”
At the same time, as China’s AI-enabled cybersecurity advancements demonstrate, there’s an opportunity cost that comes with failing to adopt cutting-edge technologies like artificial intelligence fast enough.
“Commanders have to decide what their objectives are and understand how AI technology can help them achieve those objectives,” said Maj. Gen. (Ret) Kim Crider, Founding Partner at Elara Nova and the former Chief Technology and Innovation Officer at the United States Space Force. “But we also have to leverage AI at scale, with the whole operational enterprise and the infrastructure that supports the operator: the acquirers, the policy makers and the defense industrial base are all required to drive this technology into our operations to maximum effect.”
The first step toward this end starts with the U.S. government and industry jointly validating and auditing these models.
“Every model has a different success rate when it comes to answering prompts, so you need a testing mechanism to validate the answers you’re receiving in a way that builds confidence that the system is providing the right information,” Skinner said. “There is always a risk for periodic inaccuracies, but managing that risk is the responsibility of the commander. So we must establish continuous monitoring, continuous validation and continuous auditing to ensure that the models are operating nominally, and our allies and industry partners can help the Department with that.”
Continuous validation becomes even more critical if an adversary manages to compromise or influence a model’s outputs.
“You can’t afford to have your model exposed to where an adversary can inject [false information or inaccurate data] to change what the model is looking at,” Robbins said. “The U.S. commercial industry is the only one that can develop a model at the speed and the scale necessary to work in a fully secure environment. An operator working on a classified system cannot have their model access the ‘dirty’ internet [where misinformation and disinformation is prevalent], it has to be able to work within its controlled data environment.”
The same imperative applies to space systems, as well, which are equally dependent on cyber capabilities to function.
“Space systems have an extensive attack surface, because they’re an interconnected system that includes the spacecraft, the ground segment, the links between them, the user terminals and any extended cloud infrastructure and supply chain that may be connected to that,” Crider said. “When a traditional IT enterprise is hacked, there’s a recovery process that involves isolating the attack, rebuilding a server and restoring data from a backup. But a compromised space system might also gradually deteriorate and degrade over time in a manner that may not be noticed right away, which heightens the stakes due to the Joint Force’s dependency on space capabilities.”
But while commercially available AI tools developed by U.S. industry partners significantly enhance the opportunity to discover and proactively patch cybersecurity bugs, the ability to adopt those tools and integrate them into the network in an effective and timely manner comes with its own set of challenges.
In June, the Department of Commerce placed an export control order on Anthropic’s Mythos 5 model after citing a national security concern, a ruling which the company publicly disputed. Nevertheless, Anthropic revoked access to its Mythos 5 model to comply with the order, which meant key government agencies like the National Security Agency also lost access to a leading AI-enabled cybersecurity tool.
“Senior leaders understand the risk calculus for adopting innovative technologies, whether it’s an internal authorization from DISA or an external export control order from the Department of Commerce, so they’re continually working through that as part of their risk management,” Skinner said. “From an operational standpoint, this example drives home the need to always have a Primary, Alternate, Contingency and Emergency (PACE) plan. You have to have resilience in your cyber operations and be able to adapt as necessary to accomplish the mission.”
However, the need for resilience is a discipline already familiar to operators across the Joint Force.
“If you’re in the Navy and lose reliable access to GPS, this might mean you go back to using a sextant,” Robbins said. “It’s no different with AI models. You have to be prepared to do your own analysis if you lose access to an AI model. But an authorizing official can unknowingly take that choice away from an operational commander entirely, so the government has to ensure authorizing officials recognize that the best commercial model is the model the Department needs to win.”
To overcome this challenge and manage that risk, increased communication and collaboration between the U.S. government and its industry partners will help streamline the authorization and adoption of cutting-edge AI tools as they’re developed.
“AI needs to be built and adopted in a partnership, where there’s an active dialogue on policy so that authorizing officials can understand the model’s importance to the mission and the risk of certain controls to the mission, so they can work through those challenges together,” Crider said. “Industry can be a part of those conversations and the joint exercises to think through how the AI capability can be applied. But it’s also important for industry to recognize that their AI capability may not always be something the Department would employ for any number of reasons.”
That partnership also needs to extend to international allies and partners as well, who will also be part of the broader warfighting coalition.
“Every international partner has a different set of legal authorities, privacy rules and security processes, but we can establish a common set of mission assurance standards that they will abide by,” Crider said. “So it comes down to working toward that outcome through a degree of federated trust. This enables our international partners to maintain sovereignty in their approaches, while ensuring interoperability as we employ these emerging technologies effectively in our coalition operations.”
That’s the gap Elara Nova is built to close.
“Elara Nova is really about bringing a variety of perspectives, our partner portfolio consists of experts in mission operations, technology development, systems acquisition and policy writing,” Crider said. “With experts from all of these disciplines and careers, we can help bring these entities together so that government can more fully leverage these technologies and that industry is adept at conveying their message on how their innovative technologies can be used to meet mission needs.”
Elara Nova is the trusted global security partner delivering decisive advantage. Learn more at elaranova.com