Sandia Lab News

Securing artificial intelligence


Sandia headlines AI security panel for Tri-Valley startups

<strong>AI PANEL </strong>— Sandians Jonathan Crussell, Gayle Thayer and Amanda Dodd share their perspectives on AI security with Tri-Valley startups at an event hosted by Daybreak Labs in California. (Photo by Lisa O’Hara)
AI PANEL — Sandians Jonathan Crussell, Gayle Thayer and Amanda Dodd share their perspectives on AI security with Tri-Valley startups at an event hosted by Daybreak Labs in California. (Photo by Lisa O’Hara)

Artificial intelligence is being deployed at lightning-fast rates across industry, government and academia. While AI has the potential to improve efficiency and increase productivity, it also introduces new security risks. Can we protect sensitive data and prevent adversarial attacks? How might we ensure model integrity and trust?

Sandia wants to help find those answers and seeks to collaborate with others to share best practices for AI security and drive innovation. A Lunch and Learn on AI Security featuring Sandia experts represents a step in that direction.

The July 29 event was hosted in Livermore by Daybreak Labs, a nonprofit incubator for life sciences and deep-tech startups. Amanda Dodd, director of Computation and Analysis for National Security at Sandia, set the stage by framing the AI risk landscape from a national security perspective.

“The widespread adoption of the internet in the 1990s was probably the last time we experienced a period of innovation and rapid adoption as dramatic as the AI wave of today,” Amanda said to attendees. “Like with internet connectivity, AI is introducing poorly understood vulnerabilities, not only from adversaries, but also from new failure modes we could not imagine in a less connected, more analog world.

“Sandia would like to identify where industry can meet the analytic and assurance needs arising from AI adoption, as well as understand where the national labs are well-positioned to help address any gaps.” 

Framing the AI risk landscape

While AI seems to have taken off in just the past few years, Sandia’s work in AI security goes back more than a decade. Early research looked at how adversaries can manipulate or subvert AI as part of an attack, an understudied area at the time.

“Traditionally, security conversations focused on hardware and software vulnerabilities, but increasingly the focus is on the algorithms themselves,” said panel member Gayle Thayer, manager of the Secure Algorithms department at Sandia, in her keynote presentation at the event.

Gayle explained to participants that assuring the security and reliability of high-consequence systems, including ones that use AI, is vital to achieving Sandia’s mission. “At a high level, it means applying protection mechanisms to ensure the reliability and integrity of AI systems. In practice, that means we spend a lot of time thinking about what could go wrong.”

<strong>AI PANEL </strong>— Jonathan Crussell, right, listens as Philip Kegelmeyer discusses his research in counteradversarial data analytics. (Photo by Lisa O’Hara)
AI PANEL — Jonathan Crussell, right, listens as Philip Kegelmeyer discusses his research in counteradversarial data analytics. (Photo by Lisa O’Hara)

“We red-team AI systems to identify weaknesses, understand how they can be exploited and develop mitigations,” Gayle said. “We benchmark systems for test and evaluation so that we can better understand reliability, security and performance bounds. And we work toward engineering secure designs informed by what we learn.”

Partnering for secure AI

And that’s where Sandia can partner with businesses to balance innovation with security.

“Industry often moves faster, adopting new AI tools at risk, while government takes a more cautious approach,” Gayle said.

According to Gayle, as a federally funded research and development center, Sandia can provide an unbiased, independent technical assessment of what works, what doesn’t work and what organizations should prepare for to achieve secure AI.

Gayle and Amanda, along with cybersecurity researchers Philip Kegelmeyer and Jonathan Crussell, further highlighted the benefits of partnering during the audience Q&A portion of the event.

“Industry may have different security concerns than Sandia, but in sharing our respective concerns and approaches, we can identify areas where our interests overlap and thereby inspire grounds for technical collaboration,” Philip said.

Many emerging AI threats that pose risks to national security also translate into business-relevant impacts, such as intellectual property losses, operational disruptions and regulatory risks. Thus, investments in trustworthy AI may result in a competitive advantage.

When asked what success in AI security would look like in the next few years, panelists envisioned a future where clear regulations empower industry to own AI risks responsibly, while research continues to push the boundaries of security and reliability. Failure, conversely, would mean unchecked vulnerabilities leading to operational disruptions or potential loss of trust in institutions using AI by decision-makers, shareholders and the public.

“AI is still new and imperfect with risks — we’re the ‘in-real-time’ beta testers,” Gayle said. “Sharing common concerns and solutions will help us all move faster and smarter.”

Recent articles by Diana Hackenburg

Top