MDDI スピーチ · 2024-07-03
AiSP AI セキュリティサミットでの Janil Puthucheary シニア上級国務大臣の開幕挨拶
要点
- • AI は新たなセキュリティリスクをもたらします。対抗的機械学習(MIT が AI に 3D プリント亀を銃と誤認させた事例;McAfee が速度制限標識を改ざんして Tesla の初期 Mobileye システムを機能不全にさせた事例)および古典的脅威(Microsoft 研究者が秘密鍵と 30,000 件以上の Teams メッセージを含む 38 TB のデータを誤って漏露した事例;ChatGPT が機密情報を含む訓練データの再現に誘導された事例)です。
- • Singapore CSA は 2023 年 11 月に英国 NCSC および米国 CISA と共同で『Guidelines for Secure AI System Development』を発表しました。今月は『AI システム保護のための技術ガイドライン』について公開協議を行う予定です。
- • 「AI セキュリティ」と「AI サービスサイバーセキュリティ」が並存しています。暗黒網型 AI(WormGPT など)は高品質のマルウェア、パーソナライズされたフィッシングメール、ディープフェイクを生成できます。同様に、防御側も AI を使用して異常検出と自主的な対応を実施できます。
- • Deep Instinct 2024 年 6 月の報告:米国のサイバーセキュリティ専門家の 97% は、AI の悪意のある使用により自組織がセキュリティ事件に遭遇する可能性があると懸念しています。
- • 本日、AiSP は「AI 特別関心グループ」(AI SIG)を立ち上げました。メンバーが AI の進展を議論し、洞察を共有します。
全文翻訳
MDDI 英語原文の翻訳 · 翻訳日: 2026-05-03
Tam Huynh 副秘書長、
AiSP メンバー、
皆様へ:
おはようございます。本日、AiSP 初開催の「AI 安全サミット」に出席できて大変嬉しく存じます。
過去数年、AI は急速に拡散し、広範な領域に展開されています。これは脅威状況に著しく影響を与えています。私たちが周知のとおり、AI の急速な発展と採用により、私たちは多くの新しいリスクに晒されています。
その中には「敵対的機械学習」が含まれます。攻撃者はこれを利用してモデルの機能を破壊することができます。
a. よく知られた例としては、MIT の研究者が AI に 3D プリント製の亀を銃と誤認識させることに成功しました。異なる角度から見た場合でも同様です。
b. McAfee の研究者も、「AI が訓練されて認識する速度制限標識」に小さな変更を加えることで、Tesla の初期 AI システムである Mobileye を破壊することができました。
c. このタイプのリスクは比較的新しく、より良く理解するためにはさらに多くの取り組みが必要です。シンガポール政府技術庁(GovTech)を含む公民協働機関は、AI システムに対するこのような攻撃をシミュレートする能力を開発し続けており、それらが AI セキュリティにどのように影響するかをより良く理解しています。このように行うことで、「適切なセキュリティ護柵」を配置する支援となります。
AI は古典的なサイバー脅威にも容易に晒されています。データプライバシーへの脅威も含まれます。AI の広範な採用により、「データが暴露され、漏洩し、または破損する」という脅威表面が増加しています。
a. あなた方の中には、38 TB のデータが Microsoft の AI 研究者により意図せず暴露されたことをご存じの方もいるかもしれません。彼らは当時、AI データセットを共有しようとしていました。ファイルには秘密鍵、パスワード、および Microsoft Teams 上で送信された 30,000 件を超えるユーザーメッセージが含まれていました。
b. 「持続的攻撃」では、ChatGPT は訓練データを再現するように操作されることができます。このようなデータは、名前、住所、電話番号などの機密情報を含む可能性があります。
このような事例は、「AI モデルの安全性と信頼性」に対する一般大衆の信頼と信心を損なっています。
a. 信頼がなければ、個人と組織は、これらのツールが誤った、矛盾した、または有害な結果を出力するのではないかと懸念する可能性があります。
b. これは逆に、産業が AI の利益を最大化できるかどうかに影響します。また、私たちが AI の力を借りてシンガポールのデジタル経済と社会のさらなる成長を促進できるかどうかにも影響します。
私は、産業のプレイヤー、特に AiSP とそのパートナーが「AI をより安全にする方法」についての議論をリードしているのを見て嬉しく思います。私たちは皆、「ユーザーとシステムを保護しながら、同時に成長と革新を促進する信頼できる AI 環境」の構築において役割を果たすことができます。
政府の観点から、シンガポール・サイバーセキュリティ庁(CSA)は業界パートナーおよび外国の同僚と協力してきました。システム所有者が「AI 採用方法」の決定において使用すべき明確なガイドラインを開発しています。
a. 例えば、2023 年 11 月、CSA は、英国国家サイバーセキュリティセンター(NCSC)および米国サイバーセキュリティ・インフラストラクチャセキュリティ庁(CISA)と共に『Guidelines for Secure AI System Development』に共同署名しました。
私は、CSA が今月『AI システムの保護に関する技術ガイドライン』(Technical Guidelines for Securing AI Systems)について公開パブリックコメントを募集することを発表できて嬉しく思います。
a. この「自発的な」ガイドラインのセットは、AI セキュリティに関する既存のリソースを補完することを目的としています。シンガポールのシステム所有者に対して、適用可能な実践的措置を提供し、システムとユーザーへの潜在的なリスクに対応します。
b. 私たちは、エコシステム内のすべてのメンバー、特に AiSP メンバーおよび国際パートナーに対して、「これらのガイドラインをどのように改善するか」についてのフィードバックを提供するようお招きしています。私たちは、AI がさまざまな文脈とユースケースで使用されていることも理解しています。私たちは、これらのガイドラインが実践的で有用であることを望んでいます。
c. CSA は、今後数週間で公開協議の詳細についてさらに情報を共有します。共に、AI ツールのセキュリティを強化したいセキュリティ専門家に対して、有用な参考資料を提供することができます。
私は、業界パートナーと専門家が、自分たちの責務を果たし続けることを望んでいます。悪意のある脅威に直面しても、AI ツールとシステムが安全を保つことを確保するために。たとえ技術が継続的に進化していても。
「AI のサイバーセキュリティ」
これらの取り組みと同時に、多くの組織も考えています。「AI の悪用に駆動される攻撃」から自分たちをいかに保護するかについて。
a. 私たちの多くは懸念しています。生成型 AI が悪用され、説得力のある、個別化されたフィッシング電子メールが生成されるのではないかと。ユーザーをフィッシング リンクと添付ファイルをクリックするように誘導します。脅威行為者はまた、説得力のある深層偽造を作成することができます。ユーザーをそれが真実だと信じさせ、誘導するために。
b. サイバーセキュリティの特定の層面では、「ダークウェブレベルの AI」(ダーク AI、例えば WormGPT など)の出現と上昇を見てきました。これは、AI が精密なマルウェアの製造に使用できることを示しています。これらの脅威は、既存のシステムでは検出が難しい可能性があります。
これは国際レベルの懸念事項です。例えば、2024 年 6 月の Deep Instinct レポートでは、米国のインタビュー対象のサイバーセキュリティ専門家の 97% が懸念しています。彼らの組織が AI の悪意のある使用により安全事件に遭遇するのではないかと。
「AI の悪用」についての懸念は自然なことです。しかし同様に重要なのは、AI がいかに「サイバーセキュリティ業界の善のために奉仕する」力になることができるかを考えることです。脅威行為者がこのテクノロジーを自分たちの活動に統合しているのと同様に、防御者も、AI が自分たちの仕事にもたらす利益をどのように活用するかを学ぶ必要があります。
私たちの多くはすでに見ています。AI が安全運用の「価値倍増器」になることができると。適切に使用された場合、AI は防御者がより高速で、より大規模で、より高い精度でリスクを識別するのを支援できます。私たちがより迅速に対応するのを支援します。これにより、私たちのチームはサイバー脅威への対応において、より効率的で、より効果的に機能します。
より洗練された脅威に対してさえも、AI は『競争の場を平等にする』ことに役立つことができます。既に我々は、機械学習アルゴリズムが『異常検知および潜在的脅威への自律的対応』のソリューションにおいてますます多く採用されているのを目にしています。また、業界が現在我々が保有するサイバーセキュリティツールを強化するために AI をいかに活用するか、そしてどのようにして『決定的な優位性』を獲得するのに役立つかについても期待しています。
「AI 特別関心グループ」の立ち上げ
AI はいまだ進化を続ける新興技術です。今後数年間、我々は引き続きユースケース数の増加を見ていくでしょう。同時に、我々はまた管理すべき新しいリスクを発見するでしょう。我々はこれら二つの優先事項の間で『繊細なバランス』を保つ必要があり、『安全な領域内での革新』を実現する必要があります。
そのため、我々の技術専門家は、この技術の発展と進化に追いついく必要があります。特に、信頼、安全、サイバーセキュリティの領域で働く同僚たちです。
a. これは、『AI をいかに導入するか、既知のリスクをいかに管理するか』に関する優れた提言を行うのに役立ちます。
b. また、『AI は安全の原則に基づいて開発されるべきである』というより広い対話の形成に役立つことができます。
本日、AiSP は『AI 特別関心グループ』(AI SIG)を立ち上げています。
a. このグループは加盟企業に、AI の進展について議論し、重要な洞察と経験を交換し、コミュニティと彼らの知識を共有するためのプラットフォームを提供します。
b. 加盟企業はこのプラットフォームを使用して、『AI との共存と発展』を図りながら、サイバーセキュリティ業界がデジタル領域の信頼性と安全性をいかに継続的に確保するかについて議論することができます。
c. AI がデジタルインフラストラクチャの不可欠な構成要素となる際に、これらは重要な議題となります。
関心のある加盟企業は、AiSP 事務局に連絡し、SIG への加入方法をご確認ください。将来の対話が円滑に進むことを祈ります。
結語
我々全員は、AI の継続的な安全性を確保することに自分たちの役割を果たすべきです。これは、AI を十分に活用しようとする際の、我々の組織とユーザーの信頼に影響するでしょう。
a. さらなる指引を必要とする方にとって、CSA のガイドラインは有用な出発点となるでしょう。今後数週間、公衆がいかにしてそのガイドラインにアクセスでき、CSA にいかようにフィードバックを提供できるかについてご注視ください。
同時に、我々は AI がサイバーセキュリティにもたらす機会を認識することもできます。我々はこの領域の発展に追いつき、『敵対者に対する戦いで証明された』AI ツールの採用を推奨する必要があります。
我々はまた、脅威環境が進化する際に相互に相談することができる、専門家と同僚からなるネットワークを維持することができます。AiSP 加盟企業は『AI SIG』から始めることができます——これは Tam Huynh 氏が主宰します。
本日の会議が実り多いものになることを祈ります。大変ありがとうございました。
英語原文
MDDI 公式サイト原文 · 取得日: 2026-05-02
Assistant Secretary Mr. Tam Huynh,
AiSP Members,
Ladies and gentlemen,
Good morning. I am happy to be joining you today for AiSP’s first AI Security Summit.
Over the past couple of years, AI has proliferated rapidly and been deployed in a wide variety of spaces. This has significantly impacted the threat landscape. We know that this rapid development and adoption of AI has exposed us to many new risks.
This includes adversarial machine learning, which allows attackers to compromise the function of the model.
a. A well-known example is how researchers at MIT were able to trick AI to think that a 3D-printed turtle was a rifle, even if the turtle was viewed from different angles.
b. Researchers at McAfee were also able to compromise Tesla’s former AI system, Mobileye, by making small changes to the speed limit signs that the AI had been taught to recognise.
c. This class of risks is relatively new and we need to do more to understand them better. Both public and private entities, including the Government Technology Agency of Singapore, have been developing capabilities to simulate such attacks on AI systems, to understand better how they can affect the security of AI. And by doing so, this will help us to put the right safeguards in place.
AI is also vulnerable to classic cyber threats, including those to data privacy. In particular, the widespread adoption of AI has led to a growth in the threat surface for data to be exposed, exfiltrated, or damaged.
a. Some of you may have heard how 38 terabytes of data were accidentally exposed by Microsoft AI researchers, who were trying to share an AI dataset. The files included private keys, passwords, and more than 30,000 messages sent by users, on Microsoft Teams.
b. In other types of attacks - persistent attacks - ChatGPT can also be manipulated to reproduce its training data, which may contain sensitive information – like names, addresses, and phone numbers.
Incidents like this undermine public trust and confidence that AI models are safe, secure, and reliable.
a. Without trust, individuals and organisations might fear that tools will produce incorrect, inconsistent, or harmful output.
b. This, in turn, affects whether the industry can maximise the benefits of AI, and whether we can leverage the use of artificial intelligence to drive further growth in the digital economy and society in Singapore.
I am heartened to see that industry players, including AiSP and its partners, are leading discussions on how we can make AI more secure. We can all play a part in fostering a trusted AI environment that protects users and systems, while facilitating growth and innovation.
On the government front, the Cyber Security Agency of Singapore has been working with industry partners and foreign counterparts to develop clear guidelines that system owners should use, when making decisions on the approach to adopt AI.
a. For example, in Nov 2023, CSA co-sealed the “guidelines for secure AI system development”, which was developed with the UK’s National Cyber Security Centre (NCSC) and US’s Cybersecurity and Infrastructure Security Agency (CISA).
I am pleased to announce that CSA will also be releasing its “Technical Guidelines for Securing AI Systems” for public consultation this month.
a. This set of voluntary guidelines are intended to complement existing resources on the security of AI, and provide practical measures that system owners in Singapore can use to address potential risks to systems and users.
b. We invite all members of the ecosystem, including Members of AiSP, and international partners, to provide their feedback on how we can improve the guidelines. We understand that AI is used in a wide range of contexts, and across multiple use-cases. We want to ensure that these guidelines are practical and useful.
c. CSA will release more details on the public consultation in the following weeks. Together, we can provide a useful reference for security professionals looking to enhance the security of their AI tools.
I hope that industry partners and professionals will continue to do their part to ensure that AI tools and systems are kept safe and secure against malicious threats, even as techniques evolve.
AI for Cybersecurity
In parallel to these efforts, many organisations are also thinking about how to secure ourselves against attacks that are driven by the misuse of AI.
a. Many of us are concerned about how generative AI can be misused to generate convincing, personalised emails that trick our users into clicking phishing links and attachments. Threat actors can also create convincing deepfakes and trick our users into believing misinformation and disinformation.
b. Specific to cybersecurity, we have seen the use and the rise of dark AI like WormGPT, which shows that AI can be used to create sophisticated malware. These threats may be difficult for existing systems to detect.
The concern is international – for example, in Jun 2024, Deep Instinct reported that 97% of cybersecurity experts surveyed in the US were concerned that their organisations would suffer a security incident, caused by malicious use of AI.
It is natural that we are concerned about how AI can be misused. However, it is just as important for us to consider how AI can be a force for the good of the cybersecurity sector. Just as threat actors integrate this technology into their operations, defenders need to learn to master the benefits that AI can bring to their work.
Many of us have seen how AI can be a valuable force multiplier for security operations. If used properly, AI can help defenders identify risks at greater speed, scale, and precision, which can help us to address risks more quickly. This can help us to make our teams more efficient, and effective, as we defend against cyber threats.
Even for more sophisticated threats, AI can help to level the playing field. We have already seen an increase in the use of machine-learning algorithms in solutions to detect anomalies, or to mount an autonomous response to potential threats. I look forward to hearing how the industry can use AI to improve the range of cybersecurity tools we have today, and how this can help us to gain a decisive advantage.
Launch of AI Special Interest Group
AI is still an evolving, emerging technology, and we will continue to see a growth in the number of use cases in these next few years. At the same time, we will discover new risks, which will need to be managed. We will need to strike a careful balance between these two priorities, to ensure that we innovate in a safe domain.
And in doing so, our tech professionals need to stay up to date on how this technology develops and evolves – especially for those of us who work in trust, safety and cybersecurity.
a. This will help us to make good recommendations on how AI is adopted, and how we can manage the known risks.
b. It will also help us shape the wider conversation on how AI should be developed, in line with the principles of safety and security.
Today, AiSP will be launching its AI Special Interest Group.
a. This group will provide a platform for members to discuss AI developments, exchange key insights and experiences, and share their knowledge with the community.
b. Members can use this platform to discuss how the cybersecurity sector can continue to ensure the digital domain is trusted, and secure, while co-existing and co-developing with AI.
c. These will be critical topics as AI becomes an integral part of digital infrastructure.
Interested members can reach out to the AiSP Secretariat for details on how to join the SIG. I wish them the best in their future conversations.
Conclusion
We should all play our part in ensuring that AI can continue to be safe, and secure. This will affect the confidence of our organisations and users as they try to make full use of what AI can offer.
a. For those who need more guidance, CSA’s guidelines will be a useful place to start. Please keep an eye out for details on how the public can access the guidelines in the coming weeks, and how to provide your feedback to CSA.
At the same time, we can be aware of the opportunities that AI can bring for cybersecurity. We can keep ourselves abreast of developments in this space, and advocate for the adoption of AI tools that prove to be effective against our adversaries.
We can also maintain a network of experts and peers that we can consult, especially as the threat landscape develops. AiSP members can start with the AI SIG, which will be chaired by Mr. Tam Hyunh.
I wish you a series of fruitful discussions at the conference today. Thank you very much.