Cisco AI Defense allows organizations to Discover the AI workloads and applications across your distributed cloud environments, detect misconfigurations and security vulnerabilities, and protect AI applications against rapidly evolving threats, including prompt injections, denial of service, and data leakage. While at Cisco Partner Summit, I had the opportunity to chat with Barry Yuan about the capabilities of AI Defense and get some more detail in how it enables and protects AI in your environm
Transcript
Auto-generated captions, lightly cleaned. Speakers are not separately labeled.
Hey everybody, we’re out here at Cisco Partner Summit and I ran into Barry here talking about AI defense and you gave me some information about the policy enforcement and the testing and all of the things that it does. Can you give us some more information about what it is? >> Yeah. Okay. So AI defense really is trying to secure the whole life cycle of your AI application starting from the far left, right? So what kind of components that you’re actually implementing into your environment? Do you know like more than 100 of you know AI assets like you know those are like maybe models large language models or some data sets that you know they might already have back doors built into them right so you need to be able to identify that and don’t implement that into your environment right and so we help you discover all of your assets so where are they hosted right now right and then the second thing is we can help to scan all of those assets and making sure there’s no back doors and uh there’s no obvious reasons why you know maybe it can run malicious code in it. We can show you all of that detail. And then the third thing is we actually run red teaming which is like attacks you know against your AI. We throw like thousands of them at your application at your model to actually validate how good the built-in guardrail is in your application. And a lot of businesses when they do this, they actually do this manually, but they it takes a long time, you know, we say seven to um multiple weeks, right, to actually do this manually because you have to send all of those different prompt injections at your AI and you try to do this manually, it doesn’t work. And another thing is AI is constantly evolving as well. like your your model, you’re sending it a lot of data, you’re fine-tuning it, and every time you fine-tune it, we found out that, you know, um it’s 30% more sus susceptible to uh new attacks. So that is just, you know, it’s basically forgetting its own guard rails over time. So that’s why we need to benchmark it and really measure like how good it is across its life cycle. So that’s very important. But after that, now we know like where are the gaps, right? where are the potential things that could go wrong with your AI application. Then we can provide a runtime guard rail around your application. Now this is where you’re actually sending the prompt and responses through either our gateway or our API and we tell you yeah this is good you know send it or this is not good because we explain all the reasons behind it. So this is a real-time guardrail. So that gives you a very um you know holistic protection around your application. So these are the four things that we do overall and we have three different formats right so you know uh different forms. So one is uh the easy button is customer could just consume our SAS uh cloud right so it’s because it’s fully cloud hosted Cisco hosted and uh you send all of your prompt responses to us right and then we we tell you a but a lot of people say I I don’t trust Cisco I don’t want to send all that to Cisco so you can actually deploy our gateways into your cloud so all the prompt responses is staying there right and uh you’re not actually sending it to Cisco which is the uh middle option and the option to the right uh to the right is on prem. So this is actually the AI pot that you just saw uh AI defense is already built into the AI pot as a security uh you know utilizing our guard rails and we can do validation of your assets locally as well. So that data will remain on prem but the control plane is always in the back end. So, you know, this is still based on Cisco’s cloud, but you know, that’s just where you configure your policies, you push it down to your onrem stuff, right? So, there’s still a little bit of cloud piece, but the data can retain on that box. So, hopefully that makes sense. >> Yeah. So, we were talking about some of the the testing with the prompt testing and then of course the guard rails because we still want to >> enable people to use AI but put some some guardrail so they trust it as well. And now also something interesting of course me being from the Splunk acquisition there’s some Splunk integration going on with defense. Can you tell me more about that? >> Sure. For sure. Yeah. So we have native integration into Splunk. So whenever there’s a violation of your policy, we call those events and all of those events get sent to Splunk and it has all the fine details with everything that you know why it violates our policy and we map it to industry standards like either this is OAS uh top 10 LM risks that explains what type of risk it is. Uh and also you know uh when it comes to atlas you know miter atlas we m map it to like all the different techniques uh that the bad guy was using you know to to get in right so uh so with all of those additional detail and you can actually see the prompt and response if you allow us to send you that data as well so your security team doesn’t have to come to AI defense just to see those events they can see all that in Splunk right >> yeah that’s really incredible a lot of >> a lot of flexibility here So if I want to go get some more information about what we just talked about, where can I go learn some more? >> Yeah, so we have a ton of resources on sales connect. Um, so some of them are available to partners, some are Cisco internal, but uh most of them are available uh some public as well. Uh so I have some videos that actually talks about quite detail, you know, how does businesses uh build AI applications and how do we uh secure it with guard rails, with validation, all of those capabilities. uh four different uh videos and uh also there are labs as well. So I I actually made a hands-on lab I’m happy to share. So you can actually get some hands-on experience with AI defense as well. >> That’s really incredible, man. I appreciate you for your time. >> Yeah, thank you so much.