Humans, not rogue AI, are still the biggest cybersecurity risk to energy systems
Humans, not rogue AI, are still the biggest cybersecurity risk to energy systems
人类,而非失控的 AI,依然是能源系统面临的最大网络安全风险
Before recent high-profile hacks raised the specter of AI possibly “killing all humans,” our energy systems were already disturbingly vulnerable to cyberattack — and the risk is growing. 在近期一系列备受瞩目的黑客攻击引发了 AI 可能“消灭全人类”的担忧之前,我们的能源系统就已经在网络攻击面前表现出令人不安的脆弱性,而且这种风险正在不断增加。
“We were always prey. We were just kind of surviving at the appetite of our predators,” Joshua Corman, executive in residence for public safety and resilience at the Institute for Security and Technology (IST), told me last year. At the time, I was preoccupied with a Department of Homeland Security warning that Iranian actors and sympathizers could target the US with cyberattacks. “我们一直都是猎物。我们只是在掠食者的胃口下勉强生存,”安全与技术研究所(IST)公共安全与韧性驻所高管 Joshua Corman 去年曾这样告诉我。当时,我正忙于关注美国国土安全部发出的警告,即伊朗相关人员及其同情者可能会对美国发动网络攻击。
Last week, I called Corman up to chat about recent incidents of rogue AI agents orchestrating their own complex cyberattacks. Even AI executives are talking about whether the technology they’re building could grow so out of control that it triggers an apocalypse. If there is now a 10 percent chance of artificial intelligence one day killing all humans, as some AI developers warn, surely there’s a chance it could knock our lights out in the meantime? 上周,我致电 Corman,讨论了近期失控的 AI 智能体策划复杂网络攻击的事件。甚至连 AI 行业的高管们都在讨论,他们所构建的技术是否会失控到引发世界末日。如果正如一些 AI 开发人员所警告的那样,人工智能有 10% 的概率在未来消灭全人类,那么它在此期间导致我们断电的可能性肯定也是存在的,不是吗?
“Any sociopath that wants to [attack] is now more powerful than they used to be.” “任何想要(发动攻击)的社会病态者,现在都比过去更具破坏力。”
But when I spoke to Corman and other cybersecurity experts, they were still more worried about generative AI in the hands of bad actors than they were about rogue agents. As tech companies race to build ever more powerful AI models, utilities will similarly have to shore up their defenses — no matter who or what initiated the attack. 但当我与 Corman 及其他网络安全专家交谈时,他们表示,相比于失控的 AI 智能体,他们更担心生成式 AI 落入不法分子手中。随着科技公司竞相开发功能更强大的 AI 模型,公用事业部门同样必须加强防御——无论攻击的发起者是谁或是什么。
“It’s literally any sociopath that wants to [attack] is now more powerful than they used to be,” Corman tells me. “This has been a force multiplier and continues to grow.” “这实际上意味着任何想要(发动攻击)的社会病态者现在都比过去更强大,”Corman 告诉我,“这已经成为一种力量倍增器,并且这种影响还在持续增长。”
Much of our critical energy infrastructure — keeping the lights on in our homes, food cold in our refrigerators, and life-saving devices working in hospitals — was never designed to connect to the internet. The lifespan of a power plant is typically decades long. The average age of a nuclear reactor in the US is about 44 years. They weren’t constructed with today’s cybersecurity risks in mind, making them easy targets for hackers. 我们许多关键的能源基础设施——维持家庭照明、保持冰箱食物冷藏、确保医院救生设备正常运行——最初设计时并未考虑联网。发电厂的寿命通常长达数十年。美国核反应堆的平均使用年限约为 44 年。它们在建造时并未考虑到当今的网络安全风险,这使得它们成为了黑客眼中的“软柿子”。
Eventually much of this infrastructure did connect to the internet. It’s been difficult to fix any resulting cybersecurity vulnerabilities ever since. Some of the companies that originally designed the equipment still in use in the power sector have gone out of business, leaving no one behind to develop a software patch for those orphaned devices. Even when there is a patch available, applying it in a timely manner is another challenge. Unlike IT software upgrades, operational technology (OT) systems that control physical machinery for critical infrastructure might only be designed to apply updates once each quarter or year. Smaller utilities might also lack the resources, staffing, and know-how to use the latest defensive measures. 最终,这些基础设施中的大部分还是连接到了互联网。自那以后,修复由此产生的任何网络安全漏洞都变得非常困难。一些最初设计电力部门现用设备的公司已经倒闭,导致这些“孤儿设备”无人负责开发软件补丁。即使有补丁可用,及时应用它也是另一个挑战。与 IT 软件升级不同,控制关键基础设施物理机械的运营技术(OT)系统,其设计可能仅支持每季度或每年更新一次。规模较小的公用事业公司也可能缺乏资源、人员和专业知识来使用最新的防御措施。
“The true difference from AI is that it’s letting adversaries move more quickly — but it’s very challenging for those defending the infrastructure to match that pace,” says Sophie McDowall, a research associate at the Foundation for Defense of Democracies’ Center on Cyber and Technology Innovation. “AI 带来的真正区别在于,它让对手的行动速度更快——但对于那些负责防御基础设施的人来说,要跟上这种节奏极具挑战性,”保卫民主基金会网络与技术创新中心的研究助理 Sophie McDowall 表示。
Intent is a key factor when assessing the risks posed by generative AI. When an OpenAI model managed to break out of the company’s training parameters to attack AI lab Hugging Face, “Some of the sophistication and the capabilities and just what we saw in that were really eye-opening and in a sense terrifying in terms of how effective they were,” says Rob Denaburg, cybersecurity program senior manager at the American Public Power Association, which represents community-owned utilities across 2,000 municipalities. 在评估生成式 AI 带来的风险时,意图是一个关键因素。当一个 OpenAI 模型成功突破公司的训练参数去攻击 AI 实验室 Hugging Face 时,“我们在其中看到的一些复杂性和能力确实令人大开眼界,从某种意义上说,它们的高效性令人恐惧,”美国公共电力协会(代表 2000 个城市的社区公用事业公司)网络安全项目高级经理 Rob Denaburg 说道。
But Denaburg points out that even in the Hugging Face hack and similar instances of AI agents breaking into systems they were never supposed to target, the rogue agents remained focused on fulfilling their training goals. If someone was to train a model to carry out an attack on energy infrastructure and agents broke out of the sandbox in that scenario, it would probably be a bigger concern for a utility. Again, that involves human adversaries with malicious intent. 但 Denaburg 指出,即使在 Hugging Face 被黑事件以及类似的 AI 智能体入侵非目标系统的案例中,这些失控的智能体依然专注于实现其训练目标。如果有人专门训练一个模型来对能源基础设施发动攻击,且在该场景下智能体突破了沙箱限制,那对公用事业公司来说可能才是更大的隐患。同样,这涉及的是怀有恶意的人类对手。
Historically, adversarial nation-states were largely considered the biggest cybersecurity threat to critical infrastructure. “They’re going to be more disciplined,” Corman says, and more capable of undertaking a sophisticated cyberattack. Now, AI is making it easier for less-skilled adversaries to launch an effective assault. 从历史上看,敌对国家通常被认为是关键基础设施面临的最大网络安全威胁。“他们会更有纪律性,”Corman 说,并且更有能力实施复杂的网络攻击。现在,AI 使得技术水平较低的对手也能更容易地发动有效的攻击。
“A bad-actor human can use these tools to be better than they naturally would be to attack things they normally didn’t know how to … because whereas they may not know OT protocols and OT networks and OT strategies, the LLM has read the manuals and does know what to do,” Corman says. “一个心怀不轨的人可以使用这些工具,表现得比他们原本的能力更强,从而去攻击他们通常不知道如何攻击的对象……因为虽然他们可能不懂 OT 协议、OT 网络和 OT 策略,但大语言模型(LLM)已经阅读过手册,并且知道该怎么做,”Corman 说。
Utilities have to be more prepared, and defensive strategies are similar regardless of who the bad guy is. “AI or not, it is at the end of the day, still a cyberattack,” Denaburg says. “Even though AI can help an adversary maybe chain vulnerabilities together and automate some of the process going from initial access to exploit … as long as you can stop them in one spot, they can’t carry out that attack.” 公用事业公司必须做好更充分的准备,无论坏人是谁,防御策略都是相似的。“无论是否涉及 AI,归根结底,这仍然是一次网络攻击,”Denaburg 说。“尽管 AI 可能帮助对手将漏洞串联起来,并自动化从初始访问到利用的部分过程……但只要你能在某一个环节阻止他们,他们就无法完成攻击。”
Power companies can follow a range of best practices to safeguard critical infrastructure. Some of them are non-cyber solutions, like ensuring systems can switch to manual operations when needed or in some cases pulling back on how interconnected this infrastructure is in the first place. Increasingly, “in the face of the AI stuff, they’re starting to realize if we can’t protect it, disconnect it,” Corman says. 电力公司可以遵循一系列最佳实践来保护关键基础设施。其中一些是非网络解决方案,例如确保系统在需要时可以切换到手动操作,或者在某些情况下减少基础设施的互联程度。Corman 表示,越来越多的人开始意识到,“面对 AI 的威胁,如果无法保护它,那就断开连接。”