AI Model Provenance and the Limits of Country of Origin
Latest Interviews
•
19m
AI model provenance is quickly becoming a top security question for enterprise buyers. Amy Chang, Head of AI Threat and Security Research at Cisco, joins Alan Shimel on Techstrong TV. Furthermore, she explains why country of origin is a poor proxy for real model risk.
About Amy Chang
Amy has spent about two decades in cybersecurity with a recent focus on AI security. In addition, she now leads the Cisco team studying how models fail across the full development life cycle. Consequently, her group covers red teaming, mitigations and industry best practices.
Why AI model provenance matters
Amy shares that Cisco publishes an open LLM security leaderboard for frontier and open weight models. Furthermore, common jailbreaks and prompt injections hit up to 80 or 90 percent success in five turns. Therefore, guardrails alone are not enough for enterprise deployments.
She also treats agents as untrusted entities inside any deployment environment. Meanwhile, prompts that are too narrow or too broad both create exploitable gray areas. As a result, security teams need layered controls and clear scope for every agent.
Beyond country of origin
Amy details new research where two independent methods traced technical lineage across US and Chinese models. In addition, some US built models shared clear lineage with Chinese ones. Consequently, country of origin becomes a weak signal without deeper AI model provenance data.
She points enterprises toward the Cisco AI Defense GitHub for a model provenance kit and fingerprints. Meanwhile, Cisco has donated CodeGuard to the Coalition for Secure AI. Therefore, more open transparency and shared tools can help defenders make safer choices.
Amy also flags the AI Supply Chain Provenance Explorer as a free public resource. Furthermore, it reports license restrictions, countries of origin and security notes for many models. Consequently, buyers can align AI model provenance data with their own risk tolerance before deployment.
Explore more artificial intelligence coverage and the latest Techstrong TV interviews.
For more information please visit cisco.com
Up Next in Latest Interviews
-
Solving AI Data Center Power at the P...
AI data center power sits at the top of the modern infrastructure agenda. Hans Hasselby-Andersen, CEO of Lotus Microsystems, joins Alan Shimel on Techstrong TV. Furthermore, they show how AI data center power efficiency now beats what legacy voltage regulators can deliver.
About Hans Hasselby-...
-
Nir Sabato
-
Root Evidence Rethinks Vulnerability ...
Vulnerability Management Needs Better Evidence
Alan Shimel speaks with Jeremiah Grossman and Robert Hansen during Techstrong TV’s Black Hat coverage. The discussion focuses on vulnerability management, exploitability and the long-running challenge of deciding what security teams should fix first....