Mythos and Glasswing: Openness Transforms Cybersecurity
Le brief IA que les pros lisent chaque soir
Les 7 actus IA du jour, décryptées en 5 min. Gratuit.
Inclus dès l'inscription : notre sélection des meilleurs guides & comparatifs IA.
Choisis ton rythme
Gratuit · Pas de spam · Désabonnement en 1 clic
Mythos and the Impact of Integrated Systems
The announcement of Mythos and the Project Glasswing marks a turning point in cybersecurity. Mythos, a cutting-edge AI model, stands out for its ability to process software code, a skill that aligns with a growing trend of language models excelling in this area. What sets Mythos apart is its integration into a system that allows it to quickly detect and correct software vulnerabilities. This distinction emphasizes the importance of the overall system rather than the isolated model in today's AI cybersecurity landscape.
The recipe for Mythos's success relies on several ingredients: significant computing power, models trained on relevant datasets, dedicated infrastructure for exploring and correcting vulnerabilities, and a degree of autonomy within the system. These combined elements not only enable the discovery of vulnerabilities but also the development of effective patches.
What Mythos demonstrates is that the combination of substantial computing power, models trained on relevant software datasets, infrastructure designed to manage the exploration and correction of software vulnerabilities, and speed made possible by this computing power can discover software vulnerabilities, find exploits, and build patches. This approach shows that the benefits and risks lie in the overall recipe, not in a single model.
It is crucial to note that AI cybersecurity capabilities are uneven and do not scale smoothly with model size or overall benchmark performance. The system in which the model is integrated plays a decisive role in the effectiveness of cybersecurity solutions.
Openness as a Strategic Lever
As autonomous systems proliferate, openness becomes a major asset. Open ecosystems distribute the crucial stages of software security—detection, verification, coordination, and patch propagation—within a community. This contrasts with closed projects that centralize these processes, creating a single point of failure. Organizations like the Open Source Security Foundation and the Linux kernel security team illustrate the power of this distributed approach.
Proprietary obscurity, often cited as an advantage of closed systems, loses its effectiveness in the face of AI's growing capabilities to perform reverse engineering. Moreover, the adoption of AI coding tools under poor incentives can introduce more vulnerabilities into proprietary code, a risk that open ecosystems can mitigate.
An argument in favor of more closed systems is proprietary obscurity, where the underlying code of a system is inaccessible. Unfortunately, this offers less protection than before. AI systems are increasingly capable of assisting in the reverse engineering of stripped binaries, which is significant since most legacy firmware and embedded code are closed, binary-only, and no longer maintained. This code represents a vast attack surface, and it becomes increasingly readable and accessible as AI tools improve.
The alternative, where each organization tries to secure itself in isolation with proprietary tools, cannot compete with attackers who coordinate and share techniques within their own communities. Open ecosystems allow for countering this advantage by providing collaboration and knowledge sharing among defenders.
Semi-Autonomous Agents and Open Source Tools
Semi-autonomous AI agents, which require human intervention for certain actions, offer a balance between autonomy and control. These systems, built on open components, allow for increased transparency and control, essential for organizations handling sensitive data. Open source tools, such as vulnerability scanners and intrusion detection systems, can be integrated to enhance defense.
Cybersecurity defense is an area where open source and AI agents can play a key role together. According to the System Card, it seems that Mythos is capable of operating with almost total autonomy, which we have advised against due to the potential loss of control. AI agents that are rather semi-autonomous, where the types of actions they can undertake are predefined and certain steps require human approval, achieve an optimal balance between benefit and risk. In semi-autonomous systems, humans remain in control, and the AI agent is responsible for specific subtasks. This is made possible through open code that organizations can run privately within their own institutions, specifying the tools, skills, and access privileges allowed in the system. With this setup, AI agents can be deployed defensively, finding vulnerabilities and assisting in remediation under the organization's control.
The semi-autonomous approach relies on the ability of humans to understand what an AI agent has done and why. This is much more feasible when the system is built on open components, such as open agent frameworks, open rule engines, and audited decision logs and traces, rather than when it is a black box. The "human in the loop" only makes sense if the human can see inside the loop.
Companies do not have to build these capabilities entirely from scratch. There exists a rich open source ecosystem of security tools, including vulnerability scanners, intrusion detection systems, log analyzers, and fuzzing frameworks, with which AI agents can be integrated.
Importance for High-Stakes Organizations
For high-stakes organizations, using open systems allows for rigorous inspection of security mechanisms, avoiding reliance on the claims of a single vendor. This is crucial when sensitive data is at stake, enabling customization and secure execution within the organization's infrastructure.
Open systems can be rigorously analyzed by internal security professionals, tailored to the organization's own secured data, modified to produce organization-specific oversight mechanisms, and executed entirely within the organization's infrastructure, keeping everything behind appropriate firewalls.
Towards a Future of Collaborative Cybersecurity
Attackers will continue to develop models exploiting vulnerabilities. The response lies in transparent and collaborative practices, such as open security reviews and shared vulnerability databases. The future of AI cybersecurity will be shaped by open ecosystems, providing defenders with the visibility and control necessary to anticipate threats.
Underlying all of this is a capacity asymmetry between attackers and defenders. Open models and tools reduce this gap by giving defenders access to the same class of capabilities that attackers can access—capabilities that would otherwise be concentrated within a small number of well-resourced entities.
Brief IA — L'actualité IA en français
L'essentiel de l'actualité de l'intelligence artificielle, décrypté et expliqué chaque jour.