Survey Highlights Need for External AI Security Reviews as Threats Mount

A recent survey conducted by HackerOne has revealed significant concerns among security professionals regarding the safety and security of Artificial Intelligence (AI) technologies. With the rapid advancement and adoption of AI, industry leaders are increasingly recognising the need for comprehensive security measures. The survey indicates that 67 percent of respondents consider external and unbiased reviews to be the most effective means of uncovering AI safety and security issues.

The report draws on data from 500 global security leaders and over 2,000 hackers engaged with the HackerOne platform. The findings underscore that nearly 10 percent of security researchers are now focusing on AI technology. This comes as 48 percent of security leaders acknowledge AI as one of the greatest risks their organisations face.

As AI red teaming gains momentum, there has been a notable 171 percent increase in AI assets being assessed on the HackerOne platform. From these assessments, 55 percent of all AI vulnerabilities reported are identified as AI safety issues.

Chris Evans, the Chief Information Security Officer (CISO) and Chief Hacking Officer at HackerOne, emphasised the irreplaceable role of human intelligence in addressing the challenges posed by AI and other emerging technologies. "Even the most sophisticated automation can't match the ingenuity of human intelligence," Evans stated, highlighting the importance of collaboration between organisations and security researchers to identify and resolve unique vulnerabilities.

Additionally, the survey highlights ongoing trends in cybersecurity, with cross-site scripting (XSS) and misconfigurations remaining the most frequently reported security weaknesses. Engagements such as penetration tests (pentests) and bug bounty programs continue to be instrumental in identifying these vulnerabilities. While pentests often uncover more systemic or architectural vulnerabilities, bug bounty programs focus on real-world attack vectors, user-level issues, and business logic flaws, with XSS as the most common weakness found.

The survey also notes a divergence in how different industries are handling security threats. Security-mature and technology-focused industries, including online services, retail, and e-commerce, are actively working to reduce common vulnerabilities. Interestingly, Web3 companies report 65 percent fewer instances of XSS compared to the industry average, suggesting a proactive approach in managing security risks.

The findings from the 2024 Hacker-Powered Security Report, available on the HackerOne website, provide invaluable insights into the evolving landscape of AI security and underline the critical role of human expertise in safeguarding technology.

Image credit: Elnur_/depositphotos.com

Source: Noah Wire Services