AI-vengers, Assemble! AI Security Every Superhero Should Know 

Cybersecurity Across UC - AI Security with an image of Drake Chang, Chief Information Security Officer, UCLA

By Drake Chang, Chief Information Security Officer, UCLA 
 
A sage uncle once said, “With great power comes great responsibility.” These words would go on to shape the ethos of one friendly, neighborhood Spider-Man as he grew into his own from pre-pubescence to adulthood, discovering his abilities along the way. To all the comic book fans out there, this isn’t a review of Spidey’s latest cinematic adventure in “Brand New Day,” though one could easily mistake those words as also describing the current AI landscape.  

From frontier AI models and vibe coding to the word “slop” taking on a whole new meaning, an entire urban dictionary could be dedicated to the AI vernacular being created to describe this day and age. 

And, as the world races to unlock the potential of AI, responsible exploration and usage need to remain at the forefront of our minds, especially in our institution’s role as premier leaders in research and discovery. Harnessing the immense potential of AI is only possible if we balance the equally substantial risks, and building security in by design helps enable a seamless experience that accelerates innovation. 

You also don’t need to be an AI adopter or power user to be affected by it. The digital threat landscape has shifted, and it is a multiverse of madness out there. Here are some AI security tips to consider, whether you are a (super)power user or a retired textile worker like Spider-Man’s uncle. 

Practice Data and Exposure Minimization 

Data is the fuel for AI, but what happens if that data were ever to fall into the wrong hands or be used for other than its original intended purpose? The same data used to train a chatbot agent on realistic interactions with our campus faculty, staff, and students could be leveraged to create the next social engineering or phishing campaign that impersonates our users or steals credentials. 

We are often overly permissive in what we share or make public in the name of convenience, transparency, or “making it work.” We also leave this information out there far longer than it needs to be, inadvertently exposing it well beyond its original intended purpose. Reducing AI security risk isn’t just about throwing up walls or barriers in front of your data or systems; it’s about asking whether we even need to keep storing, hosting, or running it in the first place. Minimizing the amount of data or systems we feed into or expose to AI models reinforces security by reducing the area of attack surface. 

This applies not only to institutional information, but to your personal data as well. When was the last time you thought about what someone (or something) could infer from your social media posts and public profile information? Now multiply that by 10 with AI’s ability to synthesize this information and identify disparate connections. Think about this before you choose to post your next story or tweet. 

Be Brilliant at the Basics (of Cybersecurity) 

Keep it simple. The same tropes that cybersecurity has been spinning for years in terms of vigilance are still effective when done with intention! AI has amplified attacks in many cases, not necessarily created new ones. More so now than ever, practice the basics: 

  • Think before you click (or deploy). 
    • AI can produce highly sophisticated, believable content, but it often contains subtle errors. Take a second to review the links and material or understand the command(s) AI is suggesting before taking action. 
    • If you are a programmer, leverage your integrated developer environment (IDE) to flag insecure coding patterns, run static tests, and validate secrets before deploying AI-generated code. 
  • Verify before you trust. 
    • Video deepfakes and extremely convincing phishing emails are prevalent with the democratization of AI-assisted generation. Treat urgent requests with skepticism, especially those involving money or access, and consider implementing a safe-word strategy with your family or network that only your circle knows. 
  • Strengthen your identity authentication. 
    • Multifactor authentication (MFA) is still one of the most effective mitigation strategies to protect your identity and data. Though it can be startling to read about all the novel MFA bypass techniques that now exist, most cyber criminals are still opportunistic attackers that will search for easier targets when faced with an initial barrier. 
    • If you are developing using AI, think about the API keys, encryption certificates, etc. being exchanged, and work with your local identity teams to rotate those non-human credentials regularly. 

Bring a Backup 

Accidents happen. Mistakes happen. Incidents happen. Exploration and experimentation in any facet, much less a capability as powerful as AI, come with inherent risks that elevate the potential of any or all of the above. Leveraging reliable backups can be the difference between a total catastrophe or a minor annoyance, whether it was an honest accident or a cybercriminal attack. 

Code repositories and version control are a developers’ best friends. Rapidly generating vibe code is great, until it isn’t, and being able to quickly revert to the “last known” good configuration comes in handy. Maintain vigilance and monitor branches to ensure code injection can’t sneak its way into the source. 

AI threat modeling in the vulnerability management space is now describing the average time to exploitation in hours instead of days. When a vulnerability is discovered, operators have virtually no time to prepare before attackers begin leveraging these flaws to compromise systems. An entire article could be dedicated to frontier AI security models, including how we fight fire with fire, but in any case, having reliable backups and infrastructure is a gift when it comes time to activate an incident response. Revisit your disaster recovery and business continuity plans considering these accelerated timeframes and the annual rates of occurrence adjusted for this AI-fueled landscape.  

Caution: Read Instructions Before Operating 

While we are accustomed to seeing this warning associated with heavy machinery or high-voltage electronics, don’t let the ease of accessing AI deceive you. While seemingly every software company is rushing to integrate AI features into their products these days, a little literacy can go a long way toward maintaining both security and privacy. Understanding the trade-offs and limitations with these tools is critical to exploring safely. Remember, when something is free, you are not the customer; you are the product. 

Many AI-powered platforms still have options to opt out of using your data to train their models, forget conversation history, and configure other security settings that help you explore more safely. The next time you have a conversation with your favorite LLM, ask it to suggest what you can do to explore more securely and privately. 

AI continues to evolve rapidly, and so do the security risks alongside it. Just like every comic series recap that starts with “When we last left our heroes…,” the AI plot advances in leaps and bounds with new chapters added each day. UC has been and will remain at the forefront of this innovation and discovery, and so we are the superheroes in our story with AI. Discovering these powers safely and practicing them securely will continue to bolster the mission and ensure these capabilities are put towards the shared benefit of all. With this great power comes great responsibility. 

Author 

Drake Chang

Drake Chang 
Chief Information Security Officer (CISO)  
University of California, Los Angeles 

Share YOUR Cybersecurity, Privacy, or Digital Risk Story! 

Do you have a story, initiative, or project to share for the Cybersecurity Across UC series? Send us information, an outline, a story you have written, or even a published story that is relevant. We’d love to include it in this new series! Submit a UC Tech News blog intake form found here.  

Questions? Email us at UCTechNews@ucop.edu.