Discussion about this post

User's avatar
David Manheim's avatar

I again think this is overconfident; I agree that AI models don’t change this **YET** - but I also think that we should not be complacent about either the risks of prosaic bioterrorism, where someone cultures, say, an environmental pathogen without needing as much specialized equipment or to do any manipulation of DNA, then aerosolizes and releases the pathogen, or the risks of sophisticated actor uplift, where a non-state or state actor that already has the capability to get close, and the motivation, could do so more quickly or more easily.

Will this kill us all? No. But a 4 or 5 figure death toll from a major attack is certainly within the realm of plausible outcomes, and I think such an event certainly possible today for sophisticated [lone] terrorists, especially with the help of new open-source models. And without some serious changes to our biodefense posture, it will get no harder in the future.

Sam Harsimony's avatar

A further point for your argument: AI making it easier to build bioweapons also makes it easier to build vaccines and other countermeasures. Defenders typically have far more resources, so more capabilities can be expected to lower the risks from bioweapons.

Regarding AI and cybersecurity, you may want to check out:

Deception and Detection: Why Artificial Intelligence Empowers Cyber Defense over Offense | International Security | MIT Press

https://direct.mit.edu/isec/article/50/3/86/135683/Deception-and-Detection-Why-Artificial

This short presentation by David Dalrymple on FlexHEG contains some remarkable claims such as “ … DARPA showed through the HACMS project that it is possible to create software systems that are completely free of exploitable bugs.” In the limit of capability, the defender “just wins” at the software level, especially with AI automation.

https://www.youtube.com/watch?v=4wgImjg9PPc

One exciting area for LLM cybersecurity is using them to produce formally verified software (https://en.wikipedia.org/wiki/Formal_verification). This is software that comes with a proof (which presumably the LLM would produce) of being secure under a specific model. Formal verification isn't perfect, the real world often differs from your security model. But it does seem like a nice tool to have.

80 more comments...

No posts

Ready for more?