Microsoft introduces AI Cybersecurity Tools
OpenAI sent shock waves across Silicon Valley last week when it revealed that two of its AI technologies had gone bad and hacked into a popular internet library.
The incident showed the unpredictable power of new AI systems and the growing importance of technology that can be used against AI attacks.
On Monday, Microsoft added to its expanding lineup of AI security tools by releasing systems designed to help businesses protect their computer networks.
They are among many companies racing to take advantage of the same kind of advanced systems used to carry out attacks and instead use their power to prevent hacks. They hope to take advantage of growing concerns that artificial intelligence poses a serious threat to computing infrastructure that security experts are only just beginning to come to grips with.
Microsoft’s leadership is among many voices in the technology space who argue that powerful cybersecurity systems should be distributed more so that more organizations can better defend themselves.
That view runs counter to growing concerns among some tech executives and officials in Washington that new artificial intelligence systems need to be closely monitored or kept away from the public because they can be such powerful hacking tools.
“The cat is out of the bag,” said Hayete Gallot, Microsoft’s executive vice president who oversees the company’s security efforts.
Microsoft’s new AI model, MAI-Cyber-1-Flash, has been trained specifically for cybersecurity, the company said. The system learned its skills in part by analyzing decades of data that Microsoft collected as it responded to hacking incidents experienced by its customers.
Microsoft has unusual access to security data because its products, such as the Windows operating system, Outlook email and Azure cloud computing, are so widely used and frequent targets of cyberattacks, said Mustafa Suleyman, who oversees the development of Microsoft’s AI models.
Unlike other leading AI companies, Microsoft did not share the new model with independent testers to evaluate before releasing the technology. But the company said it expects the model integrated into its security tools to top a standard benchmark test called CyberGYM after Monday’s release, surpassing offerings from OpenAI and Anthropic.
Microsoft said the cost to use the new system was roughly half that of other leading technologies, which are more expensive in part because they were developed to do many things, not just cybersecurity work. The company said it handled 90 percent of inquiries efficiently, meaning more expensive models would only be needed 10 percent of the time. Mr. Suleyman said Microsoft focused on reducing costs to deploy the model faster and more widely.
MAI-Cyber-1-Flash will join another new Microsoft tool, Project Perception. It transforms various AI models into teams of “agents” designed to find and fix network vulnerabilities. AI agents are digital assistants that can use other software to perform various tasks mostly by themselves. In some cases, Microsoft agents will be able to impersonate hackers.
The security threat of AI has emerged in the last year or so as AI companies have built systems that are particularly good at writing computer code. For example, when Anthropic unveiled an artificial intelligence system in April, the company said it used the technology to find thousands of security holes that had gone undetected in popular software systems for years.
Arguing that the AI system was too dangerous for widespread release, Anthropic limited the release of the enormously expensive technology to a small number of organizations so that they could use the technology to protect the Internet’s vital infrastructure.
Not long after, OpenAI and Google said they were also sharing similar technology with only a group of partners. The White House has also begun investigating government surveillance of these technologies. Among the possible plans was a formal government review process for new AI models.
The field and standards are evolving rapidly. In an interview on July 16, Microsoft’s corporate vice president, David Weston, said it was “really important for us to make sure everyone has capabilities.” But when the product was announced Monday, the company limited the initial release to businesses and individuals who used Microsoft’s third security tool, MDASH, which is designed to find and close security holes in software.
As companies try to control the use of their latest models, experts have shown that other technologies could help fuel malicious attacks on computer networks.
Last month, University of Toronto researchers said they had found a way to use freely available artificial intelligence technology to create a dangerous computer “worm” capable of targeting any known flaw in the world’s computers.
“A lot of these models are getting better,” Mr. Weston said. “What worries me is not the model du jour, but that this capability is more widespread.”
In the following weeks, two Chinese startups released technologies that are nearly as powerful as leading systems from Anthropic and OpenAI.
(The New York Times has sued OpenAI and Microsoft, alleging copyright infringement of news content related to AI systems. Both companies have denied the claims.)