現在および将来の状況下におけるAIシステムのセキュリティ確保
Utimacoが発表したeBookによると、組織はセキュリティリスクをAI導入の最大障壁と認識している。AIの価値は組織が保有するデータに依存するが、モデル構築やトレーニングにおけるセキュリティリスクが存在する。
Source Article
元記事を日本語で読む
本文に関係しない購読案内、埋め込み通知、サイト内プロモーションは除いています。
Utimaco [email wall]が発行したeBook『AI Quantum Resilience』で引用された調査によると、組織は、自社が保有するデータへのAI効果的な導入における主要な障壁としてセキュリティリスクを認識している。
AIの価値は組織が蓄積したデータに依存する。しかし、そのデータを用いてモデルを構築し訓練することにはセキュリティリスクが伴う。これらのリスクは、推論時点(例えばプロンプトエンジニアリング)に存在する、より広く知られた知的財産への脅威に加わるものである。
同eBookの著者らは、組織はAIの開発および実装プロセス全体を通じて脅威を管理する必要があると述べている。同時に、企業はセキュリティプロトコルを変更する準備を整えることができ、また整えるべきである。量子コンピューティングを利用した復号化ツールが悪意ある行為者に容易に利用可能となった場合、これらの変更は必須となるだろう。
Utimacoは脅威にさらされる3つの領域を挙げている:
- 訓練データは悪意ある行為者によって操作され、検出が困難な方法でモデル出力を劣化させる可能性がある。
- モデルは抽出または複製され、知的財産権を侵害する可能性がある。
- 訓練または推論中に使用される機密データが暴露される可能性がある。
報告書の著者らは、現在の公開鍵暗号は今後10年間で脆弱になるだろうと断言している。これは、実用レベルの量子システムが出現する可能性がある期間である。時期に関わらず、より組織化されたグループが現在、暗号化されたデータを収集し、量子コンピューティング施設が利用可能になった時(あるいは、もし利用可能になった場合)に復号するために保存していると考えられている。Utimacoは、モデル訓練データ、財務記録、知的財産を含む、長期的な機密性を持つあらゆるデータセットは、将来の復号化に対する保護を必要とする可能性があると述べている。
量子耐性暗号への移行は、プロトコル、鍵管理、システムの相互運用性、およびパフォーマンスに影響を与えるため、いかなる移行も数年を要する可能性が高い。報告書の著者らは「暗号俊敏性」を提案しており、これは基盤システムを再設計することなく暗号アルゴリズムを変更する能力と定義される。「暗号俊敏性」は、確立されたアルゴリズムとNISTが提案するようなポスト量子方式を組み合わせる、ハイブリッド暗号の原則に基づいている。
同eBookの著者らは、暗号技術単体では考えられるすべてのリスク領域に対処できないことに同意している。そして、暗号鍵と機密操作を通常の作業環境から隔離できる、ハードウェアベースの信頼デバイスの使用を提唱している。
企業が独自のAIツールとプロセスを開発している場合、その基盤に基づく保護は、データ取り込みから訓練、モデルデプロイ、そして本番環境での推論に至るまで、AIライフサイクル全体に拡張されるべきである。データを暗号化しモデルに署名するために使用されるハードウェア鍵は、保護された境界内で生成・保存することができる。これにより、デプロイ前にモデルの完全性を検証でき、推論中に処理される機密データは保護されたままとなる。
ハードウェアベースのエンクレーブはワークロードを隔離するため、十分な権限を持つシステム管理者でさえ、処理中のデータにアクセスできない。ハードウェアモジュールは、鍵を解放する前にデータエンクレーブが信頼できる状態にあることを検証できる。これは外部認証のプロセスであり、ハードウェアからアプリケーションへの「信頼の連鎖」の構築を支援する。
ハードウェアベースの鍵管理は、アクセスと操作を記録した改ざん耐性のあるログを生成し、EU AI法などのコンプライアンスフレームワークへの対応を支援する。
AIシステムに内在するリスクの多くは、まだ悪用されていなくともよく知られている。現在安全とみなされているデータを復号化する量子コンピューティングの能力に起因するリスクは差し迫ったものではないが、その影響は今日なされるデータとインフラに関する決定に考慮されるべきである、とUtimacoは述べている。同社は以下を提唱している:
- AI開発およびデプロイのライフサイクル全体における管理の強化
- ポスト量子セキュリティへの移行を可能にする「暗号俊敏性」の導入
- 高価値資産が関与するあらゆる場所でのハードウェアベースの信頼メカニズムの確立
(画像ソース: "Scanning electron micrograph of an apoptotic HeLa cell" by National Institutes of Health (NIH) is licensed under CC BY-NC 2.0. To view a copy of this license, visit https://creativecommons.org/licenses/by-nc/2.0)

業界リーダーからAIとビッグデータについてもっと学びたいですか?アムステルダム、カリフォルニア、ロンドンで開催されるAI & Big Data Expoをご覧ください。この包括的なイベントはTechExの一部であり、他の主要なテクノロジーイベントと併設されています。詳細はこちらをクリックしてください。
この投稿 Securing AI systems under today’s and tomorrow’s conditions は AI News に最初に掲載されました。
原文を表示
Evidence cited in an eBook titled “AI Quantum Resilience”, published by Utimaco [email wall], shows organisations consider security risks as the leading barrier to effective adoption of AI on data they hold.
AI’s value depends on data amassed by an organisation. However, there are security risks to building models and training them on that data. These risks are in addition to better-publicised threats to intellectual property that exist around the point of inference (prompt engineering, for example).
The eBook’s authors state that organisations need to manage threats throughout their AI development and implementation processes. At the same time, companies can and should prepare to change their security protocols, changes that will become mandatory if quantum computing-powered decryption tools become easily available to bad actors.
Utimaco lists three areas under threat:
Training data can be manipulated by bad actors, degrading model outputs in ways are hard to detect,
Models can be extracted or copied, eroding intellectual property rights,
Sensitive data used during training or inference can be exposed.
Current public key cryptography will become vulnerable in the next ten years, the report’s authors attest; a period in which capable quantum systems may emerge. Regardless of the timescale, it’s thought that better organised groups currently collect encrypted data and store it to decrypt when or if quantum facilities become available. Any dataset with long-term sensitivity, including model training data, financial records, or intellectual property, may require protection against future decryption, therefore, Utimaco says.
A migration to quantum-resistant cryptography will affect protocols, key management, system interoperability, and performance, so any migration is likely to take several years. The report’s authors suggest what they term ‘crypto-agility’, which it defines as changing cryptographic algorithms without redesigning underlying systems. ‘Crypto-agility’ is based on the principle of hybrid cryptography – combining established algorithms with post-quantum methods, such as those suggested by NIST.
The eBook’s authors concur that cryptography on its own doesn’t address all possible areas of risk. It advocates the use of hardware-based trust devices that can isolate cryptographic keys and sensitive operations from normal working environments.
If companies are developing their own AI tools and processes, protection on that basis should extend throughout the AI lifecycle, from data ingestion through to training, model deployment, and inference in production. Hardware keys used to encrypt data and sign models can be generated and stored inside a boundary. Model integrity can then be verified before deployment, and sensitive data processed during inference remains protected.
Hardware-based enclaves isolate workloads so that even system administrators with sufficient privileges can’t access any of the data being processed. Hardware modules can verify that the data enclave is in a trusted state before releasing keys – a process of external attestation – helping create a ‘chain of trust’ from hardware to application.
Hardware-based key management produces tamper-resistant logs covering access and operations to support compliance frameworks such as the EU AI Act.
Many of the risks inherent in AI systems are well known if not already exploited. The risk from quantum computing’s ability to decrypt data currently considered safe is less immediate, but the implications should affect data and infrastructure decisions made today, Utimaco states. It advocates:
A strengthening of controls throughout the AI development and deployment lifecycle,
The introduction of ‘crypto-agility’ to allow transition to post-quantum security,
Establishing hardware-based trust mechanisms wherever high-value assets are in play.
(Image source: “Scanning electron micrograph of an apoptotic HeLa cell” by National Institutes of Health (NIH) is licensed under CC BY-NC 2.0. To view a copy of this license, visit https://creativecommons.org/licenses/by-nc/2.0)

Want to learn more about AI and big data from industry leaders? Check out AI & Big Data Expo taking place in Amsterdam, California, and London. The comprehensive event is part of TechEx and co-located with other leading technology events. Click here for more information.
AI News is powered by TechForge Media. Explore other upcoming enterprise technology events and webinars here.
The post Securing AI systems under today’s and tomorrow’s conditions appeared first on AI News.
関連記事
今日のまとめ
AIデイリーブリーフで今日の重要ニュースをまとめ読み