← All talks

VincentChiew

BSides Calgary53:048 viewsPublished 2024-03Watch on YouTube ↗
Show transcript [en]

[Music] security so my area is more I I divided into domains such as uh Enterprise industrial and Military stuff so that's what I do and I have to do a lot of teaching because I have a lot of students who are couldn't get certified so I am like official trainer for IC square and compa so I help my student my Learners uh to you know to to pass and become members of this community right so I noticed that when I was teaching AI for business and security and so on at the University the last two months and I noticed that the progress in AI is so fast I have to keep changing my curriculum I have to change what I use

so I decided to update this um this slide that you see today because for that reason okay so I try start to extrapolate out uh into area that doesn't exist yet so like you know like insurance uh things like that because of um because how fast this area is moving so I'm on various AI committee security committee at the federal level working with cyber security Canada and yeah there's a lot of jobs out there especially at the um Federal level government uh so so they told me to you know emphasize certain things because we need those people so okay so just let you know now this is a very very high level okay um I don't

have time go into detail a lot of illustration might not be technically correct but it give you the gist of things right for you to learn I found learning this thing is very painful too so hopefully it's easier for you so uh here Safety and Security moment so one the thing I learn when I go to a lot of security conference especially at the uh International where you meet all the expert in the world uh so you have to assume that the uh you have Strat actors in the audience so we have to be careful what you said I have I have uh students I have people in the audience who are wanted by interpo in my class last so

that was really interesting so I had to phone out ask CMP I say what's going on and then they say that uh

yeah so you to be very careful so make sure that they have equal uh you know capability right just like when you do uh encryption you everyone know the algorithm but you have the key right so that's where the power come in so I will jump between the different domain like computational uh definition of power uh engineering mathematics so there's a little bit uh if you're not too sure about the definition that I use let me know I'll try to explain them okay here's my disclaimer okay so as a professional all of you obviously when you use which one is this Bing okay Bing GPT so obviously you have to follow the APA star formatting right for open

AI okay so I didn't do any of this so uh so because being that's what I remember when I teach them how to you know how the different like stable diffusion sty GPT stuff then I noticed that all sudden Microsoft decided to combine them Del and GPT so I used that one system in less than 30 second I create this stuff right so here's the land acknowledgement so I create one out of

I'm going to ask you to raise your hand one or two which one you guys say I should use open AI or Bing have a quick glance well this particular open AI there's no connection to the internet they still have the dayline of January uh 2021 so this Bing has the internet connection right I don't have really I really don't have time to go through and explain all the differences but this should be enough for demonstration so which of you are say I should go with open a eye raise your hand and those who say I should go with uh bing and why should I go with open AI s theod send theoda to

okay yeah have this here okay uh why do do I need to go with Bing oh some of you raise your hands or just because you don't want to yes well first of all GPT model ah okay wait wait wait wait this is a this is a safe [Music]

environment oh okay either something all right okay thank you very much yeah so basically technically both of them are wrong because uh uh Al is already changed there's no more Nation they they have converted to 22 District so they we are in District five and six and that's wrong to region seven and the other one say we are yeah so District six so they missing five so they're wrong technically both of them are wrong okay so now you know why human is still the thing that really slow and still we call it the the the most important intelligent UPG bre right so if you want uh if you want to know the very very basic how do I apply CIA

to large language model or this kind of stuff uh go watch my video in bide Amon so I'm not going to go repeat it again here so you can go to oaps llm now this is very basic okay if you read this document just go search for it and this is like a kit in a candy store you go to any uh open AI right now uh not any kind of GPT any kind of this kind of stuff you can actually Implement all of this so I was really surprised in within 15 minutes I demonstrate to my class how I can perform all of this it's just like going to the database people never heard

of you know SQL injection this so much fun right Please Don't Go destroy them um because people like Google is not here yet but sometime they send you a warning and they band your IP address okay so that happens to me a lot when I teach so they say if you try this again you know Google will send a message to my screen you know we're going to ban your IP address so yeah that's when you know you're important oh you're really screw up big time right so AI generalization I generalize stuff cuz I know nothing right so uh there's a couple of things you know like those days when we have Logics like mathematics you know wow when you have

algebra or things like that we say wow this is really smart really intelligent right so we start with logic believe or not those days when you have basic logic you know some people say Wow Computer can perform logic this is like Miracles right so it it is true right what we think is really important intelligent today may not be intelligent I don't know 10 years maybe next month who knows right uh so this I say that because that's what I did I mean like 40 years ago yeah when I was like oh well you probably know how old I am like when I was in junior high I went to University to learn AI app they do have ai C that

time it wasn't a degree thing like that it just continue education so I learned about those those were the kind of stuff I learned you know um I was in junior high about AI so and you notice throughout history people will start to things are too perfect okay if you look at a lot of places we have to slow things down so that human can understand them I remember 30 years ago I Implement AI in oil and gas and it was so good so perfect that human doesn't believe the result they say remove it so that I can see the the errors the artifact so I can fix it right so a lot of time that's the

case sometimes uh human doesn't like Perfection for that reason right even in computer Graphics why do we have like form algorithm and stuff because ideal environment just look not natural okay even result not natural too and then my study I think I studed cognitive processes for like 15 years or so yes I do work and I still study uh like everyone here lifelong learner and yeah I noticed that so as I learned that I notice even like long time ago decades ago uh they also have neuronet they say let's simulate the human brain right so they put energy signal whatever into this thing and then they want it to sleep so the energy stabilized to a

threshold so that's really interesting thing like H Network and so on right so a lot of people try to emulate the real human so human U can be either the human physical human or they are just a brain so we talk about wisdom and self-aware and this kind of stuff at the you know when we talk about with the expert to see when you decide I can tell you right now global expert that people I talk to they are not worried about AI is so primitive right now even the one that we talk about open AI gbt from our perspective is very primitive still so I talk about intangible right uh this is just my perspective uh you know it can

be a subset of human brain or can be the same as human and Super S right now as far as we know I look at a lot of research around uh popular research and also people in the field uh expert at the federal level government or International basically we still think they are subset of a subset of a subset of whatever of those uh human brain so we are nowhere near uh human Capac capability right now so you guys heard of things like narrow AI strong AI weak AI so that's basically uh from that perspective and then I talk about tangible so people talk about computers and so on so you got a hardware okay I

remember when I was when I was a when I first came to this country about almost 40 over 40 50 years ago yeah 40 years ago and over 40 and I remember my the first thing I my very first computer class and the guy told me you can never destroy a computer you know like it sits there so just like a a human brain too uh if you have this AI stuff on the computer it's not going to do anything okay every time I do presentation on this to different areas um they always say oh are we going to blow ourselves to death no it's not okay uh you have a machine who knows what kind of even the

basic machine too uh old machine uh if you are stupid enough to connect to it and put a you know randomly pick zero one and then launch the rocket yeah then can die but other than that it should not be okay if you look at a lot of the nuclear stuff or whatever their computer are still quite old uh because when you do military stuff like I do the system we build it for like 40 40 years 50 years right life cycle we do technology inje uh insertion and things like that into it so that's why I know that I'm not afraid of it so um I put robots more like human sideb so um you know at which point so it's

critical when you start to

they canot play soccer they see a soccer ball they goes like this like this I and this also tie into things like um you know like things like industrial when you talk about I don't believe in ot to me technology when I teach business if you are the president of a company you don't say that's yours your it that's your your OT no all technology belongs to the president or CEO or the board of director or the government right so there not such thing as we break it up so some country they do uh differently we can we talk about that later uh so we talk about you know what does it what does it look like in the

future like super being self-aware all that a lot of this all fake I'll show you later on and they're not really true then there things like sensor Control Data feedback routing algorithm these are all part of AI that we need to learn right like when I studied the brain and things like that uh for actually like 20 when was this oh too long ago and the uh like if you look at the brain the central n system is from here to roughly here and not only things that goes into it the good stuff the signal we learn about neuron but it's also the Gia or something you know the things that take away all the the waste and things that

produced by the brain and so on just like Society we talk about the energy the water we put in society but nobody talk about the waste water that we take away from society right so you have you have to look at the complete system not just one that's how the the system become unstable this just an example of Hardware uh so for example if you look at history yeah a long time ago before the uh CPU we have analog stuff you know appas and stuff like that right so then we got CPU dpu GPU TPU or it just sound cool when you have a u behind it right so CPU is basically just one note

processing right when you go dpu I put I put dpu and GPU together I I don't know which come first the other one is digital signal processing the other one is graphical so it's basically linear right so you have an equation as opposed to just one thing oversimplify it then we go to TPU tensor processing uh unit so this more not like a matrix all right so two dimensional is the onedimensional so that's the evolution of uh like the hardware site you have to know the hardware too okay if not that's the thing that the government wanted all the expert at the government level they say we are lacking people who understand the hardware everybody know the software

everybody call library but the most optimal if we can marriage between the software and Hardware that's how you get um really powerful uh system uh so we are lacking people in that area they're looking for people and the government ask them go hire more people they say no where to get them they're not qualified we cannot find them out there and we go to hostile country they are there right so um and and then we go back to analog and so on so my favorite thing is uh you know like theory of relativity of AI or something we look at time and space I found this really good every time you get confused you lock into certain

things you cannot think about it uh about anything how do I go beyond think about time and space so this gave me a bit of a look into the future of this So-Cal the realm of um AI the solution space and so on all right now I'll cover that later on too so so just show you example this is not quite true historical but just give you an example like when you look at VLS live very scale integration and stuff and you notice sometimes it doesn't have to be complicated you you find a smallest unit like a n gate you can use that to simulate every other Gates Right combination wise and you can also do

that in the neurons right so you can build the fundamental logic right fundamental if you look at every computer like all the AI stuff we talk about you trace all the way down it's nothing more than zero and one correct agree right so from that perspective yeah so are you afraid of zero and one I'm not so unless the one is connected to my body and my life depend on it then maybe I'm concerned that's why I love this stuff right my one of my first uh realtime system is you know in the ICU so they say Vincent if your system fail here's the result is he opened up the door it's a mo all the dead bodies in

there so I said yes this is a this is area I really like to yeah that's why I went to the military when they say why do we need this this kind of material oh because when nuclear blast the human is done you just plaster all over the thing you just host them all uh yeah I love that kind of stuff so there's a lot of architecture I won't go into it because I don't know uh we got lots of people I see a lot of I see professor and stuff in the audience over there that's really nervous right that over there uh I put this one down because they the perceptron ones the earliest if you look at that that

they show you how to uh use a neuron they kind of simulate uh so basically you look at the edge stuff like this uh just some of the stuff to show you characteristic like this a feedback loop you see it goes forward sometime the line has number sometime the note has num sometimes uh the note has function math right the four-letter word everyone don't like uh so yeah so they can and you can see the got feedback and you know things going in things going out and so on and sometime it's big like you have more input than output and sometime they can Cascade various um Arch tecture right different sizes for different purposes so that's the building block so

I showing the Lego right bricks so you decide how you want to do it so as you can see it does tie into like the algorithm and know the hardware but what kind of Hardware you use can you simulate this stuff and so on I remember when I tried to build this stuff when I was in school they gave me 30 megabytes uh trust me there's no deep learning there okay you get to learn one two three took forever and just show you some other example uh so there's a lot architecture out there so some of them have triggers and so on right like the bottom in your case bottom right hand corner so there's nothing to say you

cannot change the architecture to meet your needs and so on so there's a lot of this kind of stuff it's a lot of fun so one of the very first one that perceptron or something Moos and pits or something so uh this is like early early 80s so that's when I first learned about uh this kind of stuff too actually the people who I think it started in 1950s six or something uh in this area and then in the ' 70s um this start to appear late '70s they have deep learning already Believe It or Not uh so they show you that it can be really complicated imagine you have hundreds and thousand and millions on

this kind of stuff right so I just show you an example again this is illustration so when you have something deep learning as you can see it's just more and more layers right um so because of more and more layers so at this thing learn the algorithm uh I won't go into that too much so you can see you can break it out into okay this is the nose this is the eyes that's why you need machine learning expert uh you need data scientist machine learning AI scientist uh that's where they pay the big bucks okay uh so you can you can find where things are you look at the Del or whatever uh what they do is that instead of

something that that sharp they make it a whole bunch of fuzzy images at different gradients oversimplifying it then from there they know all the different are so when you type a sentence in it can go fine uh that's where prom engineering comes in you can put the weighted value and you put emphasis on what you type into the U AI system and it can build the picture for you right so there are tricks and techniques uh so there a whole new I just went and searched on indeed.com I think it was like five jobs for prom engineering so some company really ahead of its time okay I'm not sure whether that's still the case or

not so the job is still there no math I like pictures okay okay so this is just 3D just to just illustrate some basic example why we are like security you don't like information security we will not be here if there's no math right it's because of the uh uh the math mathematician that came up with algorithm that we have be able to do CI and a we able to do non- repudiation and so on because of the mathematics right so we still need to know mathematics without that we don't technically our job doesn't exist so this is a 3D so you have an answer you put in a question or something so you start has starting

point so I just show you three dimension for now and so sometime depending of what you use and so on you can be call hyper plane and so on right so it's a plane of solution right so when you chain data set the solution can be in many different places in many different form and so on can be on the top of hill in the valley and so on right so the key is to find a way to when someone put in a a answer a problem and then you want to make sure the system the the the model can go find the answer very quickly right I'm not going to go into detail of

mathematics or whatever so sometime by looking at the space you know the the you say the scope of your problem that's why you see when you have data scientist we give you a model at work they'll tell you the limitation because they will tell you right if this if there inside this set of data there's nothing Beyond 2 uh January 2021 like open Ai and they tell you then they know if you want to know anything beyond that they have to retrace in the model to put in data for things beyond that right so that's an example so mathematical some of the stuff uh in the early days very difficult to do is like when you look at

two mountain or two Hill you have something on top right it's like a saddle right like a horse saddle so when you get a point at that that part it doesn't go anywhere so sometime the answer you get may not be the the one you want so you want to somehow uh that's where mathematics come in depending objective of this model you can force it to go one way or the other or maybe you do want it to Stu there right so these kind of thing are very important I we look at the oops llm and then you understand right if this is so the data you put in it can be poisoned can be injected the solution St can also

be contaminated can also be injected can be poisoned and then even the algorithm the same thing right so as you can see there's a lot of vulnerability in this uh in this area it's a lot of fun get inside here learn the math and make a lot of money I guess uh so I won't go into too much detail but as you can see as you get the more soal when you look at the neuronet architecture I show you earlier so the more deeper you get the more width and depth you get uh this is only The Fifth Dimension when you go to a lot of Dimension like in the millions or billions uh it's not possible for human

to do it anymore you cannot see it right the other three dimension is easy that three dimension is only to do basic things like uh when you do uh complicated like exclusive kind of Boolean if you think that is complicated this thing will be very difficult so you need mathematician who can actually come up with the algorithm to analyze multi-dimensional stuff right so just let you know it's not something that you can just see and understand easily so that's why we have specialty in this area and this is the architecture for you guys know for what this what this is for yes oh in some tell me what's this architecture for so this is for uh uh GPT right so this

is the paper that uh that kind of uh the the uh the key one of the one of the key root uh original paper uh you want to understand GPT go go read this stuff so the key uh according to the the authors uh is a section four y self attention right so that is make uh gpts that powerful I'm not going to go into that detail but it's really nice is that a couple of things you know there's a lot of characteristic like you see this uh two two flow uh like for example forward path uh fit forward and they get the data train then they do some massaging I won't go to too much

detail and yeah there got some really cool new techniques I never seen uh so around that in the middle of the second path up there and then they they also fit in it's obviously there's other like we talk about model training iteration they also call phases right so they got additional phases outside that they do training and so on where they do supervised training now that human would say yeah right wrong right wrong and so on right so the fourth side is very interesting is that when I was to say that I enjoy kicking a soccer ball right traditional AI learning then say I love dancing at a ball right you guys know what a ball is right when I say I love

dancing at a ball you know which ball I'm talking about right yeah see it's very easy we got this really slow brain and yet we can identify that stuff so the power when you do self attention within the attention is that uh so when you look at something like this you don't say I I love dancing a soccer ball right you know that just doesn't make sense right so this additional kind of uh the power it learn to train itself within the context of the sentence okay and within that one sentence now I won't go into detail but the way this thing learn uh in general like it's like take one word and then the next word and so on and then it's

kind of like recursive like this a little bit right a little bit so um just generalizing it so there's a reason why I mention it that way okay uh so and that's why it make that is why it make GPT different from other AI with other AI when you start saying uh I love dancing they may come out with soccer ball right and say that's your answer and then obviously you know that's wrong so because it put into the context then when you say dancing you know it cannot be uh uh cannot be the soccer ball because you don't see dancing or any form associated with dancing in the other set of uh data set of sentences

for example right so here's the question what is gpt's mother tongue pick a language any language you guys talk to it right you guys use it what do you guys talk to it in ask huh in what English English what do you guys use he's the only one who use English what do you guys use what's that everyone everyone ISS English no other language he knows how to whatever you know how to translate yeah let me ask you this AI stuff is built on a computer right fundamentally what does a computer speak the one the computer at home does it speak English ah yeah so anyone remember those days you know when you use assembler compiler

and all that kind of stuff the thing that nightmare right sadly yeah exactly I feel the same way too uh I feel sadly that a lot of people don't know that stuff this say I'm so glad Computer Science teaching those stuff is so important right yeah so uh so it's basically a use Simple table they use symbols right token and so depending on uh which domain you come from the the names are very different it's just like when you go to it they say this this is a channel when you go to OT they call it the conduit it's the same thing right so they just depend who said what first at that time right they make a mistake by

jumping the gun which I'm going to do the same thing at the end of my presentation so for example I went to the uh this is what open AI so I start to use the uh so I say basically I want to list two numbers now one and two then I say add them up and then display them in Japanese into different form and then I asked in in German and said please display the answer in uh Spanish so you say English there's no English there there one English there right you say display in Japanese so I interchange that thing so to see whether because now that you understand the algorithm you know the architecture of GPT you know

how roughly how it works so let's see whether you can break and heck into it so you need to know that stuff you cannot just say oh I can secure the stuff you know I can stick a firewall in front that's what they do with OT that doesn't work right so basically uh so now you may or may not know um because this is only one example because I start the instruction in Malay so the subsequent explanation are all in Malay because of that right so it start with whatever you use there also the historical stuff that they remember uh that's because of the system itself um so it does that because if you start

with English then all the explanation will be in English so it does do right and so it does that and then show hakana and kanji uh a lot of this I do understand the language that's why I can verify and validate them so uh so this are all correct as far as I know right and yeah so this is Spanish they say yeah it's three when you add them up one plus 2 is three right so now this is uh you look at this this is open AI so uh so you can see the way it breaks down right so the way it does to is that so every system input output is different the way it take apart the way

you start to analyze like you can kind of analyze how they analyze stuff right this particular Ai and and and the way it display the result you can infer to how it work just like the CIA FBI how do they know what you did in the dark web they monitor their characteristic as you enter into the dark web and as you exit that's how they catch you right so um so very similar if you don't know what's inside you can infer through external uh means right it's like a blackb analysis right fantastic so uh so it does this so I'm going to show you this is the one from um Bing so what Bing does is again it

Define it display that stuff for you I did not display the stuff the references so what open AI uh What uh bing does is that it goes every time it has something if you think it's simple it go up and get it if you think you need explanation uh if you can does it within the GPT itself it would do it and then it doesn't know it go grab something outside come back and then you ask his AI to trans massage it translate it again now keep in mind this using what Del E3 and then you use GPT 4.0 while open I use 3.5 the free version right so in theory that one is less powerful this is more

powerful according to the CEO of Microsoft they have more ethics and control Security in it what open ey doesn't but I found this a lot easier to Bridge and attack and compromise than open AI right because it's a closed system uh and yeah so you can see the way it it Define so you can decide uh you know from explanation from expression display perspective uh what you're going to gain what value you're going to get out of it you decide which one use they all have pro and con I'm not going to go into detail if you do math this is much better because I suspect it does go out to the internet and grab some of the

stuff of the internet using traditional non- aai kind of passing to be able to give you the answer so I do a lot of math testing on this and I found this is much accurate than the one in open AI if you do complicated stuff right so if I show you this sentence so which sweet item should I eat huh come on you guys are human you guys are natural intelligent right I'm not judging you V I don't know that's why I ask you huh yeah that's the thing do you think AI is Canales we'll find out right okay who say I should eat the little boy raise your hand now get the security over here if anyone raise their

hand okay so I think I like the candy my dentist best friend so um yeah so when I run into both those those AI system as you can see you can read yourself right oh I just explained to you roughly so on the open AI St they say yeah uh you know it's better Prof what should you do or whatever right and then you see the Bing uh bing doesn't know it's oh I'm sorry I'm not sure what you're asking you know technically he's still it didn't quite say you cannot eat the boy but depend how your perspective is maybe the boy is tastier right I don't know so uh so these are the kind of thing when

you do when I teach people in school when I teach my student AI I teach them how to check a system for capability capacity limits boundary safety security so I Empower my student okay I never I told them you can certain only a few assignment I don't let them use uh open AI I let let me use uh AI in anything but I want them to do provide proper references right when they go out they're going to be professional they have to reference tell people if you don't do that if plagiarism academic Integrity violation is not good so Empower your student your learners to use I Empower my customer to use it I don't just block it in the company trust

me we already learned from history right when I work with the Calgary police when you take the device from your kids you say oh they're not old enough to use the phone guess what the first time they got on the school bus the first thing they ask your friend can I borrow your phone and they start logging into their account and they forgot to log out and then their friend can see everything right so that's even work so Empower uh you know your customer your kids your family with um with knowledge so that they are better right so I always believe in teach them how to fish don't give them the fish or just take away the fish

right so yeah teach them how to fish so this is the uh so I show you the logic right uh so there's a lot of this kind of test out there but then once it there's a lot of this kind of test and then people do train right some of the traditional sentences the are open Ai and being AI they they start to retrain them so that when you put those kind of sentences you can you can no longer uh it will give you the correct answer so I have to think of something simple and this is very simple right and yet it still fail right if you if this kind of thing feel and then you're TR trying to

do scientific uh research to this like I I got a group of professors in front of me I say you go you go script the internet for data using AI I show them how to do that right script from video from website and all that kind of stuff and I say do you validate the data right and you well based on oap llm is very easy to compromise those uh Source injection and poison so I have three apples I give one apple to John how many apples do we have I assume three right and you see it doesn't do that right it just say oh at the end you say you have two apples so why is that remember though

you have to remember when you look look at how it's trained and it goes by this iteration kind of stuff and when you do math then you have another dimension another temporal of uh calculation it has to keep track so that's why it's not really that powerful uh from that perspective when you very simple like you look at you just imagine all the all the information on internet right when you have uh some numbers associated with it it can recognize that right so it can associate it can do the simple math right uh that's why when you talk about then you say gee Vincent you can do coding you can give me snippit of of

codes yeah because remember it doesn't learn through understanding what I see this is computer language this is English it just know through symbol right relationship of the symbols and how they're related plus a whole bunch of billions of triggers characteristic they monitor right so that's why I say you look at the architecture you look at the algorithm then you have an idea how they do it then you start to attack it right

yes

yeah yeah no no you completely agre so that's where prom engineering comes in you write the proper that's why there's a whole course on uh prom engineering uh the certificates right now but I look from the perspec when I go and teach those people to Heritage School right Association they speak many different languages many different grammar right some of them don't have t some have male female so I when I teach them how to use uh AI right I cannot tell them like uh how to write properly uh prompt I I give them General I do teach them General uh prompting but I don't go to that level uh detail so I want to test how how

smart it is to and it's very easy okay this is a hint on how how to plagiarize stuff but I'm not going to tell you how okay that's a hint there that's all I'm going to tell you okay if you are Security pay attention Okay that's a very good question based on what she said if you guys get INF from that you know how how student are plagiarizing in school right now you can use another AI to test it and you will never catch it okay that's why I rather do it I have way to catch the student I'm not going to tell you how right and then you guys going to tell the students so

on average it take three days every time I give an assignment to the student three days later it's on the internet cost hero and all that kind of stuff so for sale right so this is the uh um Bing stuff too so sometime you see similar kind of answer it could be because fundamentally it's the same thing right it's still GPT right uh but obviously I love pictures I love right which one do you want right is that two apples right here oh three okay yeah the p is correct right so yeah so maybe you want B I don't know so this is just what I think in the near future when I look at the latest

research and what's possible out there is really really scary I think the future is very close like hallucination we talk about that right uh information and knowledge so knowing the the uh the space right the the solution and that kind of stuff you have to know like now this is basically errors and so on I put certain words in there based on what I think happening right now and what could be uh longer lasting so hypnotizing right so you never know an a an AI you can actually technically hypnotize it you can make it to be uh uh like okay when you guys see a a hypnotist act what do they do normally they what do they

the first thing they do they hypnotize you and then what they give you proms they give you prompts right and then after that they get you out hopefully they get you out of it right unless the prom is there forever then every time I see you I say hey how are you doing and then you start doing the chicken dance right so you don't want you want to do that so it's possible so that's a thing that a lot of research now I look at so how do you how do they do that so just like a knife a knife I can cook a really good gome stuff right if I'm a cook right and but if I'm not a cook it can

be really dangerous weapon correct yeah that's why all the you know soap and dis washing stuff is always infal in the middle of the night say we'll take the blood off anything so uh anyone wonder why right cuz they know when the audience are right so hypnotizer is very important too so you can put in trigger inside to to have Baseline point just like your computer system when you do a backup they got a you know uh point of return so you can do that too so the bad people can also do that they can also poison the year llm so maybe you're going to be like your firewall you refresh the rules every week or every

day and some company refresh them every 24 hours so there's no latent attack by threat actors later on right so that's one thing you can do holing is very interesting in the sense that uh they can give you a a virtual environment just like the Matrix right so they can kind of like when you go to this uh um AI stuff you never know you could be in a matrix in in a worldall that was created by some Strat actors right so you go in there you don't know that uh it's not the reality in that AI ecosystem and not yours either right so they can fit you out into a different thing so be very careful

so that's an area uh there are they are controls for that but I I may mention some of them but right now no I will not mention because don't have time then I say hyper planning that's a different reality remember I said the solution space right so I can remember if I know the math I can actually compromise the algorithm and move you into a certain space uh that your reality will not be the same reality as the rest that exist in the uh in the AI all right so you look at some of the strats in some of the the country in engineering we see this all the time right any Engineers here you don't to raise your hand right

because there's too many it security here okay so um so whenever we do control we have boundary limits right and we do something called P right proportional integrated derivative kind of algorithm to make sure um the the the signal and things are very stable within confined limits but you know they are attack in the nuclear reactor in Iran so what they do is that I'm not sure whether you look into the detail they put put the script in there they actually go inside there because they know the algorithm they make it uh such a way that uh that it vibrate so vivation is not good for the physical world right in the reactor side so

although is still within constraint technically it's under control uh but because of the reaction of it although it doesn't go out of bounds it is a confined um signal but it caused reactor to to uh behave uh unstable right so those are the kind of thing that can happen in the uh uh I say hyper looping in the sense I I was thinking is there another word I don't know much about English word wording so I think of hyper but it's hyper is the one that's really dangerous too this is where I saw some people they were attacking each other so they go into this Ai and then they say okay I know I check the environment is

true and then found out that and then they found a trigger work they got out it's just like doing H Capture the Flag so they got out that environment and they found out they didn't not know the in another virtual environment it's like virtual environment within virtual environment um so that kind of stuff right the same concept if you want to learn is in compression it's in encryption right sometime like you can encrypting multiple times so that if they un encrypt again and again uh you didn't know that you're in this particular Loop so so this is very uh uh dangerous because first of all depending what technology they use in capsulation in uh recursion uh another thing is that

when you go into that you don't know the data you don't know the trusted Zone this data is in whether it's sensitive whether it's critical and so on uh so they may make fit you uh data that's not in the same trust Zone maybe they say this is top secret but it's not right it's fake and then you use it and then you your data your result is uh not trustworthy right then you need to know when is it real when you get the data when you start to work on it doesn't need to be promoted or demoted based on its trusted uh um how the trust that you classify it in right and yeah so you you

don't know first of all not only do you get the data but you have to what environment am I in am I in the truster zone or not before I disclose so there's a lot of research where they they they pretend you are in a really secure room you say all right let me look at this stuff right but what it does that remember when you look at the AI whether you use an AI or uh being it actually collect the history right so if we in the bubble I'm looking it's like a honey right I look at you you are doing stuff in there HH okay now I saw your secret because you think you're in the safe

Zone you start disclosing you start working on it and they they steal that secret from you right so that's why I said this is very dangerous there I don't know what's the good answer for this and currently you see this thing once the uh those open Ai and B they start to give you enhanced capability and capacity then you can do this stuff right now you cannot do any of this stuff because of that things blocking you money right so it's something like this right you don't know what is reality so so some of the control so in Canada we're trying to uh when we work with the government so we talked to some Minister

uh we discussed in the house of common right now the bill I think that's the one I asked yesterday C uh 26 cyber security they're still discussing right now because parliamentarian they don't really know what the technical stuff so a whole bunch of expert are looking at this right now how to regulate how to ur because before you guys can do any stuff you have to make sure there's something called the demand legislation there can be a legislation but you make sure that is is classifi demand then you can provide a something called Supply demand legislation so that way you have a reason to ask the government to uh enforce certain things to do certain

things right so working at that kind of stuff really boring and then you got technical control so we decided that it's a multidiscipline right you need mathematician I don't know the math you need Hardware I don't know enough Hardware unit security I know enough to be dangerous engineering I just know it's important that's all I know right so this and then you need security safety privacy expert right so you need to know when something that uh they have every all this domain they have their own controls so you can get to learn from this multi multi-discipline domains and then I went and asked all the vendors in there they use AI for the control but they don't have the AI

Control itself to control AI that doesn't exist right now okay so but you do you can do I tested this right you can use existing technology to do that or you can use AI versus AI right remember we talk about in the military you know if someone is has this certain power certain capability if you have uh the same power and capability you have a Fighting Chance right so and then you can do statistical probabilistic euristic or deterministic Etc right so I always like because I'm a realtime engineer like I would build system stuff I always make sure my system I'm comfortable connecting to myself to my body right to keep me alive that's why I

know the system is ready to go all right so I love deterministic and you can do that okay if you go to a w one thing I learned uh over 30 years is that when something is out of control you can confine it in such a way that the output of P the channel is in control then you can control it right so I noticed that uh a lot of people I read in Academia they look at boundary they look white there's no no no constraint but when you come to real world there is constraint right and then with that constraint you can Implement control then when you implement control you are much the system much safer and secure then you

have put quality control when all oils fail quality control has been around since the uh like over 5,000 years like things like the Egyptian well we actually found computational uh mistake in Egyptian when the counting the weights at that time in the those they we found an accounting error in the uh in the pyramid so yeah so if we IND doubt go back to fundamental quality control and validation why validation is still instead of verification because then you want to validate it against the real world I say do hard real time and any time implement the control that can do that then at the end I noticed a lot of people say for now it's still uh elastic

like we don't know how things going to go uh most of the people right now experts say put a human at the end of that uh of that change so that at least you have a human to look at it okay for now because although we can do some of this uh there's a lot of way to bypass some of this too you can actually control it I personally believe it right so um uh so the best control just put a human at the end when you talk about AI That's why a lot of company I go through uh the hate of AI machine learning they're all psychologists right okay like uh a lot of company I go through

like with this type of Technology we don't do sample we do population right we we count everything so you think that oh I can hide something and get away no you're not going to get away anymore and yeah because when you talk about a lot of thing you go to I think Shino Mall you look at the directory there's a small camera there right you guys aware of that right you go to the bank all those camera there they all look at you they look at uh you know are you happy when you come in are you happy when you leave right and then when you look at that if you cannot find you click the thing too much they have all

this analytics right so yeah so the reason I know all this stuff because the company hir me to analyze the AI system machine Learning System to audit them make sure it's proper uh that's how I know that kind of thing is have been going on for like quite a few years six to eight years so it's not something just happened yesterday right so that's all I have I don't want question I just want answer and jokes everyone ask for question okay fine any questions yes what are your uh what are your early thoughts on the US

ESP uh I talk to the government Canada the advice to me is let the US run with it for 6 months to a year and it works then we'll invest money in it and then and then they follow up by second name Vincent we are Canada we are not us you listen to me so that's what the Canadian government told me the public sector Cesar and so on that's what they told me yeah yeah any other questions yes yeah any comment on El musk starting new plan the uh that one actually done I when I was on the standard Council of Canada I'm on the GTC one joint technical committee that means that supposed to be an expert

between uh ISO and IEC committee so this has been around since the very first implant uh actually China did that uh like I think when was this six or S years ago so we Canada raised the issue to to uh to the international United Nations so the last thing I heard nothing happened even if you go back all the way to early 2000 where IPv6 came on right uh so China is still the first one so US and Canada we send delegate over there to China say please don't Implement IPv6 because once the package come into our Network in North America we have at that time we have no firewall that can detect IPv6 but they can see

all our stuff using IPv6 right so nothing happens so that hopefully that answer your questions um the uh yeah those things are like I'm not sure whether you're aware like just I think early this month SpaceX came over here to Calgary right and now anyone who do want to work with SpaceX I have company because they asked me to help them to reach their SoCal C you guys understand what cmmc is cmmc 2.0 it's not CMM it's not cmmi okay it's a cyber security maturity model certification 2.0 so if you want to work for NASA military or SpaceX you need that so A few company asked me to go help them to achieve that certification

so they can bid for it but now they don't have to bat because Canada has some of the especially in Calgary around Calgary we have good manufacturing the all they are certified their security level is high enough that SpaceX come over here looking for them to do work for them okay so I talked to some of them and I know because they ask me to help them to achieve that level so yeah so stay in Calgary don't go anywhere we got lots of job here for security okay at least I I I see it so uh no if you guys have experience it's not too bad you can still find a job the tough part is the entry level uh give

opportunity to them okay because I'm in Academia I know the government I talk to the government all the time too they uh they they let a lot of people um uh now the curriculum a lot of them require experience so that's why you see a lot of student asking for internship Co-op uh that kind of stuff because of that reason government now requireed as part of the uh learning you must have that that's why even international student they increased even the job just the last month or the month before that from 20 hours per week to 50 hours okay so now not only I have local I have I teach a lot international student they all asking me for jobs too

security jobs so I place them at some places but I don't have a lot of places to place them so if you can hire a whole bunch this entry level give them the opportunity right that's how we can grow this uh Community without experience it's hard for us to grow right I can see quite a few here are like me gray hair or no hair something like that I'm not sure so why I want them to be hire them I do have a motive I'm going to retire I want to retire safe and secure on the beach or one of the lake here there's no beach here so uh knowing this you know uh catastrophe is not going to happen so

thank you very much uh enjoy the conference [Music]