Splunk Tech Talks
Deep-dives for technical practitioners.

Understanding Generative AI Techniques and Their Application in Cybersecurity

WhitneySink
Splunk Employee
Splunk Employee

Watch On-Demand

Artificial intelligence is the talk of the town nowadays, with industries of all kinds wondering how they can harness the power of Generative AI. Although ChatGPT has received most of the attention, generative AI actually encompasses a variety of technologies and techniques, including Large Language Models (LLMs), Generative Adversarial Networks (GANs), Diffusion Models, and Autoencoders.

Generative AI and Cybersecurity_Jan 2024 Security Tech Talk.png

For security teams, each of these techniques has something to offer, so it’s important to understand their differences and potential uses. Join members of the Splunk Machine Learning for Security (SMLS) team, Abhinav Mishra and Kumar Sharad, for a comprehensive overview of these techniques, including:

  • The particular strengths of different generative AI techniques
  • Real-world security scenarios that these techniques can support
  • Practical tips for implementing these techniques to enhance threat detection

Watch Now On-Demand

WhitneySink
Splunk Employee
Splunk Employee

Your Questions Answered

Q. How significant of an accuracy improvement is achieved with fine-tuned LLMs as compared to traditional approaches In order to measure improvements in accuracy, it’s important that you establish baselines before employing LLMs. Then, you can start implementing and fine-tuning your LLMs and measure the difference in accuracy. While the overall improvement may be small, we found that typically the model performed well for harder instances.

 

Q. What are the cost considerations while deploying LLMs?  One important cost consideration to keep in mind is the GPUs required to run LLMs. In general LLMs are resource hungry but with time, we are seeing more focused and efficient implementations.

 

Q. What are the privacy considerations when using Generative AI models for security use cases?  Preserving privacy while learning from sensitive data is always a challenge. However, these risks can be mitigated by adding carefully calibrated noise while training. Techniques such as Differential Privacy allow us to provide strong privacy guarantees.

 

Q. Probably not ML related, but is there a way/site to differentiate photos AI created on sites like this-person-does-not-exist from real ones?  This is very challenging. Once the adversary becomes aware of the defenses employed to filter out AI-generated images being used for malicious intent, they can adjust how they train the LLM to evade these defenses. So while today, my machine learning classifier may be able to correctly identify real versus fake images, the adversaries could adapt tomorrow.

 

Q. Beyond DGA and mis-information can you think of any user uses of generative AI by adversaries ? can you give some practical examples of generative models applied over data in the security field? or maybe a reference/link to such examples and use cases?  TWhen it comes to adversaries’ use of generative AI, there are two things to keep in mind: 1. Not every adversary is equipped to use LLMs and generative AI, given how sophisticated they are. 2. For those adversaries that are employing these technologies, it’s a bit of a cat and mouse game. For example, just like we can train LLMs to help detect certain threats or threat indicators, adversaries can then train their own LLMs to evade detection. Security focused Generative AI use cases: 1. Detecting DGAs 2. Detecting Typosquatting 3. Detecting spam 4. Detecting phished webpages 5. Privacy-friendly data generation to train models 6. Data generation to supplement sparse datasets The above mentioned use cases can also be used by the adversary to strengthen their attacks.

 

Get Updates on the Splunk Community!

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer at Splunk .conf24 ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...

Share Your Ideas & Meet the Lantern team at .Conf! Plus All of This Month’s New ...

Splunk Lantern is Splunk’s customer success center that provides advice from Splunk experts on valuable data ...