JustPaste.it

Securing AI Infrastructure Supply Chains Through Resilience by Design

In a time of disruption-driven business, operational resilience is no longer optional, but a necessity. From cyber threats and systems failures to economic crises, pandemics like COVID-19 and international political upheavals, financial services institutions must have the ability to withstand and adapt.

 

The best way to ensure resilience is to incorporate it into the very architectural design of an enterprise’s teams, processes and strategies. This is known as Resilient by Design and requires a shift in mindset from reactive crisis management to proactive risk awareness and a culture of continuous improvement.

 

Despite these new realities, many organizations continue to operate under the presumption that their existing cybersecurity controls will protect them. But this thinking is flawed. Traditional security measures, including access controls and encryption, are not designed to prevent the kinds of attacks that threaten AI infrastructure supply chains — attacks that exploit deep supply chain dependencies or take advantage of weaknesses in hardware and software that go undetected until it’s too late.

 

To tackle these challenges, a growing number of institutions are turning to Resilience by Design. The approach entails embedding resilience into the very architecture of an organization, with components such as governance, scenario testing and third-party risk management baked into the firm’s teams, systems and architectures. In addition, it includes routinely testing these resilience-critical functions against severe but plausible scenarios that would likely require external crisis interventions.

 

However, in many cases this is not enough to create a resilient AI infrastructure supply chain. This is because a lack of effective framing for how to think about data in an AI supply chain can lead policymakers and technologists to overfocus on a single data component or to conflate related but distinct data components together. In turn, this can miss a variety of specific risks that exist across different data types and use cases, which are better addressed by targeted mitigations.

 

For example, bad actors’ efforts to poison AI training data require mitigations beyond those provided by access controls and encryption, such as data filtering. Meanwhile, attackers’ efforts to insert so-called neural backdoors into the behavior of trained AI agents necessitate new protections that go far beyond the capabilities of existing cybersecurity technologies.

 

Incorporating resilience into the design of an AI infrastructure can address these and other risks, helping companies to overcome the limitations of their existing technology investments and build more secure, agile and sustainable operating models. To succeed, however, this effort will need to be broader than just the tech industry: The entire community needs to embrace Resilient by Design to help us fortify against tomorrow’s challenges today.

 

American Chamber of Commerce